Clear boundaries from day one.
BuildrPane combines authentication, row-level authorization, privacy-conscious logs, encrypted provider credentials, and explicit data boundaries for live provider connections.
Server-only secrets
Administrative credentials and OAuth tokens stay on the server and are never sent to browser code.
Workspace isolation
Supabase Row Level Security limits application data to the user’s workspace.
Minimal provider scope
Provider adapters are designed around totals and service metadata—not code, prompts, responses, or application rows.
Deletion controls
Account deletion resolves identity from the verified session and removes application data before deleting the auth user.
Current safeguards
- Supabase SSR cookie sessions and protected routes
- Row Level Security on every public application table
- Safe audit events without raw IP addresses
- Secret-redacting structured server logs
- Production-only service-role handling
What we do not claim
BuildrPane does not claim SOC 2, HIPAA compliance, a completed penetration test, or an independently certified security program. Those claims require evidence and operational maturity beyond Phase 1.
Reporting a concern
If you discover a security concern, contact the editable security address configured by Pawlicki Designs before sharing technical details publicly.