Security & Resilience
Last reviewed: October 5, 2026
Access control
Email verification is required. Organization data is isolated with database row-level security, and sensitive actions check both membership and role. Anonymous sign-in is disabled.
Data protection
Private credentials are kept out of the browser and source repository. Receipt files use private storage. Connections to the application and service providers use encrypted HTTPS transport.
Auditability
Administrative and accounting events are recorded to support review. Posted accounting entries use balanced double-entry records, and closed periods are protected against ordinary edits.
Backups and recovery
The production database uses the backup facilities included with its Supabase plan. Before serving paying customers, NaNach Systems will retain scheduled off-platform exports, document recovery ownership, and test restoration regularly. Users should retain original source documents independently.
Responsible reporting
If you believe you found a security problem, do not access other users’ data. Preserve the details and report the issue privately through the account channel used to provide service access.