CRATARA legal

Security Overview

A factual overview of controls currently built into CRATARA. This page does not claim a certification or guarantee that no incident can occur.

Effective August 26, 2026

Identity and access

  • Authentication is handled through Supabase Auth, with optional Google OAuth.
  • Protected workflows require an authenticated session and active organization membership.
  • Roles separate owner, administrator, manager and operator capabilities.
  • Customer administrators are responsible for invitations, role choice and prompt access removal.

Tenant and data controls

  • PostgreSQL Row Level Security and organization identifiers scope application data.
  • Proof of Work files use private, organization-scoped storage paths and time-limited signed access.
  • Operational evidence links to the event it supports; inventory and audit history are designed to preserve traceability.
  • Mutation endpoints validate authenticated membership and reject unsafe cross-site requests.

Application and browser protections

  • TLS is provided in production by the hosting and infrastructure platforms.
  • Content Security Policy, HSTS, anti-framing, content-type, referrer and permissions headers reduce common browser risks.
  • Evidence uploads enforce type, file signature, size, organization and role checks.
  • New supported photo uploads are re-encoded client-side to remove embedded device metadata before transfer.

Shared responsibility

Customers must secure phones, computers, scanners and email accounts; use unique individual accounts; apply least privilege; remove former workers; verify operational decisions; and avoid unnecessary sensitive data. CRATARA does not currently claim SOC 2, ISO 27001, PCI DSS or HIPAA certification and should not be used to store regulated payment-card or health data.

Report a security issue

Do not test against production or access another customer's data. Send a clear description, affected URL, time and reproduction details to asielhernandezmartinez@gmail.com. Avoid attaching live credentials, personal data or exploit code until a safe transfer method is agreed.