Quality · Production
Security and privacy
Authentication, RLS, tool permissions, resource limits, and data exposure boundaries.
Security controls
- Supabase authentication and row-level security protect canonical records.
- Private queries are scoped by user and workspace.
- Text, title, batch, turn, and retrieval limits protect expensive routes.
- Write tools require explicit authorization and idempotency.
- Vector and graph queries require workspace filters.
- Service-role credentials remain server-only.
Data exposure
- Public pages do not require an authenticated Supabase session.
- Activity and trace views expose safe events rather than provider payloads or database errors.
- The MCP endpoint is disabled unless a server token is configured.
- Infrastructure health details are protected by an optional bearer token.