Security Overview
Infinite Barakah Ventures · Cashflow OS · 10 August 2026
Tenant isolation
Every table holding customer data carries an org_id and is protected by PostgreSQL row-level security. Isolation is enforced by a restrictive policy in the database, evaluated against the signed-in user's session — not by application code that could be bypassed by a missing filter. Write permission is evaluated per organization, so a user who administers one organization holds no elevated rights in another.
Authentication and access control
- Microsoft Entra ID single sign-on, or email and password, via Supabase Auth.
- Six roles — viewer, AP team, AR team, finance user, finance manager, admin — assigned per organization and enforced on every API route and in the database.
- Support access to a customer organization is explicit, read-only and recorded in the audit trail as impersonation.
Encryption
All traffic is TLS 1.2 or higher. Data at rest is encrypted with AES-256 by the managed platform. Third-party credentials, such as Zoho refresh tokens, are stored service-side and are never sent to the browser.
Audit trail
Every create, update and delete on customer data writes an append-only audit record holding the table, row, before and after values, actor and timestamp. Per-row history is visible in the application; the log itself is not editable through it.
Hosting and backups
Application: Vercel. Database, authentication and storage: Supabase, hosted in AWS ap-southeast-2 (Sydney, Australia), via Supabase. The UAE PDPL does not require data localisation, and no transfer restriction applies to this arrangement; the region is disclosed so customers can assess it.
Automated daily backups are taken of the production database.
Payments
Subscription billing is handled by Stripe. Card data never touches our systems, so we are not in scope for PCI DSS beyond SAQ-A.
Data portability and deletion
Administrators can export the whole organization to Excel at any time, without contacting support. On account closure, data is deleted within 90 days.
Incident response
Suspected incidents are triaged on discovery. Where a breach is likely to prejudice the privacy, confidentiality or security of data subjects, we notify the UAE Data Office and affected customers within 72 hours, per the UAE PDPL.
Certifications
We are not yet SOC 2 certified. A SOC 2 Type I engagement is planned, followed by Type II after the evidence period. We answer security questionnaires directly in the meantime.
Contact
Security questions and vulnerability reports: privacy@infinitebarakah.com.