CRATARA legal
Security Overview
A factual overview of controls currently built into CRATARA. This page does not claim a certification or guarantee that no incident can occur.
Effective August 26, 2026
Identity and access
- Authentication is handled through Supabase Auth, with optional Google OAuth.
- Protected workflows require an authenticated session and active organization membership.
- Roles separate owner, administrator, manager and operator capabilities.
- Customer administrators are responsible for invitations, role choice and prompt access removal.
Tenant and data controls
- PostgreSQL Row Level Security and organization identifiers scope application data.
- Proof of Work files use private, organization-scoped storage paths and time-limited signed access.
- Operational evidence links to the event it supports; inventory and audit history are designed to preserve traceability.
- Mutation endpoints validate authenticated membership and reject unsafe cross-site requests.
Application and browser protections
- TLS is provided in production by the hosting and infrastructure platforms.
- Content Security Policy, HSTS, anti-framing, content-type, referrer and permissions headers reduce common browser risks.
- Evidence uploads enforce type, file signature, size, organization and role checks.
- New supported photo uploads are re-encoded client-side to remove embedded device metadata before transfer.
Shared responsibility
Customers must secure phones, computers, scanners and email accounts; use unique individual accounts; apply least privilege; remove former workers; verify operational decisions; and avoid unnecessary sensitive data. CRATARA does not currently claim SOC 2, ISO 27001, PCI DSS or HIPAA certification and should not be used to store regulated payment-card or health data.
Report a security issue
Do not test against production or access another customer's data. Send a clear description, affected URL, time and reproduction details to asielhernandezmartinez@gmail.com. Avoid attaching live credentials, personal data or exploit code until a safe transfer method is agreed.