Tenant isolation
Supabase Auth, company memberships, role checks, and row-level security policies isolate company data.
Security and privacy
Visit Bridge uses role-based access, parent-track boundaries, tenant-aware database policies, audit logging, and operational release checks for organizations that manage child, family, court, attorney, and scheduling records.
Supabase Auth, company memberships, role checks, and row-level security policies isolate company data.
Sensitive actions write audit events through a database RPC that derives actor identity from the authenticated session.
Generated plan records and supporting files are private, scoped, validated, and served only through controlled access paths.
Release gates include linting, typechecking, unit tests, coverage, production builds, e2e smoke tests, and a health endpoint.
Privacy, retention, support access, backup, deployment, and incident response documents are maintained in the release packet and should be reviewed with counsel and customer stakeholders before processing real production records.
Contact us to review controls with your stakeholders, or sign in if your organization already has access.