Krylant
Security by default

Trust belongs in the architecture, not the fine print.

Krylant separates tenants at the database boundary, limits credentials by purpose, validates every external event, and makes sensitive operations observable.

Tenant isolation

Every business-scoped database record carries a tenant identifier and is protected by row-level security policies.

Encryption

TLS protects data in transit. Provider tokens and sensitive integration credentials are encrypted before database storage.

Least privilege

Owner, admin, manager, and employee roles map to explicit permissions for business operations and administration.

Identity security

Supabase Auth manages verified email, OAuth, secure session refresh, password reset, and optional multi-factor authentication.

Abuse controls

Origin checks, input validation, per-identity rate limits, signed webhook verification, and replay protection guard public interfaces.

Auditability

Security-sensitive changes, access decisions, provider events, version publications, and administrative actions are recorded.

Secret handling

Secrets stay server-side, API keys are shown once and stored as hashes, and browser voice uses short-lived ephemeral credentials.

Privacy lifecycle

Consent events, configurable retention, data exports, account deletion workflows, and legal holds support GDPR operations.

Data regions

Supabase project region and private Storage configuration are selected during deployment.

Responsible AI

Knowledge sources are approved by the business, clinical advice is blocked by policy, and human escalation remains available.

Incident response

The runbook defines severity, containment, evidence preservation, customer communication, and post-incident review.

Need a security review?

Enterprise evaluation materials include the architecture, subprocessor inventory, data flow, controls, and deployment guide.