Security
Last updated: June 2026
Our Security Approach
[PLACEHOLDER] NuroTrack is built with security as a foundational concern. We implement technical and organizational controls to protect your data. We do not claim to be breach-proof, and we cannot guarantee absolute security.
Authentication and Access Control
- [PLACEHOLDER] Email/password authentication via Supabase Auth
- [PLACEHOLDER] Role-based access control (owner, admin, inspector, viewer)
- [PLACEHOLDER] Server-side permission enforcement on all write operations
- [PLACEHOLDER] Row-Level Security (RLS) on all tenant data tables
Data Encryption
- [PLACEHOLDER] Data in transit: TLS encryption
- [PLACEHOLDER] Data at rest: encrypted by cloud infrastructure provider
- [PLACEHOLDER] File storage: private buckets with signed access URLs
Audit Logging
[PLACEHOLDER] All significant write operations are recorded in an audit log with user, organization, timestamp, and action metadata.
Reporting a Security Issue
[PLACEHOLDER] If you discover a security vulnerability, please contact us at [SECURITY CONTACT — TBD]. Do not disclose vulnerabilities publicly before we have had a chance to address them.
SOC 2
[PLACEHOLDER] We are working toward SOC 2 readiness. We do not currently hold a SOC 2 report. We will not claim SOC 2 compliance until a licensed CPA firm has issued a report. See our internal SOC2_READINESS.md for the current state.