Authentication
Production accounts are intended to use Supabase Auth for email-based authentication and session management. Users are responsible for protecting credentials and reporting suspected compromise. Additional enterprise authentication options are not claimed unless documented in a signed agreement.
Encryption in Transit
Public production traffic is intended to use HTTPS and modern TLS. Connections to infrastructure and configured providers should also use encrypted transport. This page does not claim customer-managed keys or field-level encryption unless a specific implementation is documented.
Access Controls
Workspace data is scoped by organization membership and database Row Level Security policies. Roles distinguish owners, administrators, analysts, and viewers. Server-side service credentials must not be exposed to the browser. Access controls require deployment testing before each production release.
Data Handling
Research briefs, uploads, source excerpts, prompts, generated analysis, reports, comments, and operational logs are processed only as needed to provide and secure the service. Sensitive or regulated data should not be submitted until retention, provider, location, and contractual requirements have been reviewed.
Application and Infrastructure Controls
The codebase uses input validation, security headers, protected server routes, tenant-scoped storage paths, append-only audit records, and server-side secret handling. The Content Security Policy issues a per-request nonce for scripts and uses strict-dynamic; inline styles are still permitted, so style-level hardening remains an open production task.
Third-Party Providers
NCASEAI can depend on hosting, database, AI, retrieval, parsing, analytics, email, monitoring, and integration providers. Provider security, retention, data-use settings, and processing locations must be assessed as part of final deployment and customer procurement.
Logging and Auditability
Operational events, job state, integration delivery, and selected security activity can be logged for troubleshooting and audit. Logs should avoid secrets and unnecessary customer content. Retention and access to logs must be defined in the final production policy.
Incident Reporting
Suspected security incidents should be reported to [SECURITY EMAIL]. The final incident-response plan must define triage, containment, investigation, recovery, documentation, customer notification, and legal-notification responsibilities.
Responsible Disclosure
Security researchers should send a clear description, affected endpoint, reproduction steps, and impact to [SECURITY EMAIL]. Do not access other users’ data, degrade the service, use social engineering, or publish unresolved findings before a reasonable remediation period has been agreed. A formal safe-harbor policy has not yet been published.
Customer Responsibilities
Customers should use strong unique credentials, limit member access, remove former users, review exports and integrations, avoid uploading unnecessary sensitive data, verify report sources, and notify NCASEAI promptly about suspected misuse.
Assurance and Limitations
NCASEAI does not currently claim SOC 2, ISO 27001, GDPR certification, local regulatory approval, penetration-test completion, or any other assurance that is not evidenced in the repository or a signed disclosure. Security measures reduce risk but cannot eliminate it.
