Security

Last updated: June 2026

⚠️ Placeholder — Not for production use. This security page is a draft stub. Do not make unsupported security claims. Legal counsel and a security professional must review this content before publication.

Our Security Approach

[PLACEHOLDER] NuroTrack is built with security as a foundational concern. We implement technical and organizational controls to protect your data. We do not claim to be breach-proof, and we cannot guarantee absolute security.

Authentication and Access Control

  • [PLACEHOLDER] Email/password authentication via Supabase Auth
  • [PLACEHOLDER] Role-based access control (owner, admin, inspector, viewer)
  • [PLACEHOLDER] Server-side permission enforcement on all write operations
  • [PLACEHOLDER] Row-Level Security (RLS) on all tenant data tables

Data Encryption

  • [PLACEHOLDER] Data in transit: TLS encryption
  • [PLACEHOLDER] Data at rest: encrypted by cloud infrastructure provider
  • [PLACEHOLDER] File storage: private buckets with signed access URLs

Audit Logging

[PLACEHOLDER] All significant write operations are recorded in an audit log with user, organization, timestamp, and action metadata.

Reporting a Security Issue

[PLACEHOLDER] If you discover a security vulnerability, please contact us at [SECURITY CONTACT — TBD]. Do not disclose vulnerabilities publicly before we have had a chance to address them.

SOC 2

[PLACEHOLDER] We are working toward SOC 2 readiness. We do not currently hold a SOC 2 report. We will not claim SOC 2 compliance until a licensed CPA firm has issued a report. See our internal SOC2_READINESS.md for the current state.