Theme preferences
Save your colour theme in this browser for future visits. Leave this unchecked to use it only for the current session. Unchecking removes the saved choice.
Security at ContractorKeep
Security is designed into tenant access, document storage, public links, and sensitive operations from the first beta.
Last updated: 30 September 2026
Tenant isolation
Every workspace is isolated using PostgreSQL Row Level Security, tenant-scoped foreign keys, and server-side authorisation. Frontend filtering is never treated as an access control.
Private document storage
Documents are stored in private Supabase Storage. Access is checked before issuing short-lived signed download links. Public uploads use expiring, revocable, high-entropy links whose raw tokens are not stored.
File controls
The MVP accepts PDF, JPEG, and PNG files up to 10 MB. Extension, declared MIME type, stored size, and file signature are checked before a pending upload becomes a document version.
Accounts and sensitive access
Supabase Auth provides verified accounts, secure session handling, resets, and TOTP multi-factor authentication. Sensitive owner and administrator actions require additional assurance.
Audit and operations
Sensitive changes, review decisions, reminders, role changes, and billing state changes are recorded without storing document contents or secrets in logs.
Beta limitations
The controlled beta uses free hosting and database tiers. Before accepting paying customers, we will add paid backup coverage, independent object backup, recovery testing, monitoring, incident procedures, and a formal security review.