Tenant separation
Organisation membership and permissions are enforced in the database; the browser cannot grant itself access.
SECURITY & BUYER ASSURANCE
RAQOZ publishes the controls that are verifiable today and leaves certifications, service levels and security assurances unclaimed until evidence exists.
Organisation membership and permissions are enforced in the database; the browser cannot grant itself access.
Material workflow transitions emit immutable audit events. Corrections must create new evidence instead of rewriting history.
Procurement attachments use organisation-scoped private storage policies; public branding assets are separated.
CURRENT VERIFIED SCOPE
Supabase Auth handles account authentication. Organisation membership, active status and permission checks remain enforced by database policy.
Organisation-owned tables use forced row-level security and organisation-scoped workflow functions; the browser cannot grant itself cross-tenant access.
Procurement attachments use private, organisation-scoped storage policies. Public marketing assets are separated from tenant documents.
Material workflow transitions write actor and timestamp evidence to audit events that database triggers prevent from being updated or deleted.
Released workflows provide tenant-scoped transaction evidence, governed exports and SHA-256 manifests within the stated pack scope.
Suspected vulnerabilities can be reported privately to Cyclotron Technologies. Reports should contain minimum reproducible evidence and no passwords, tokens or customer documents.
RESPONSIBLE REPORTING
Send the affected surface, reproduction steps, impact and minimum validation evidence. Do not send passwords, access tokens, bank details, personal data, procurement documents or production customer data.