Quality · Production

Security and privacy

Authentication, RLS, tool permissions, resource limits, and data exposure boundaries.

Security controls

  • Supabase authentication and row-level security protect canonical records.
  • Private queries are scoped by user and workspace.
  • Text, title, batch, turn, and retrieval limits protect expensive routes.
  • Write tools require explicit authorization and idempotency.
  • Vector and graph queries require workspace filters.
  • Service-role credentials remain server-only.

Data exposure

  • Public pages do not require an authenticated Supabase session.
  • Activity and trace views expose safe events rather than provider payloads or database errors.
  • The MCP endpoint is disabled unless a server token is configured.
  • Infrastructure health details are protected by an optional bearer token.