PWEBSInstitute management

Security

Account isolation

Private database queries are scoped to the authenticated user and should be enforced by Supabase RLS.

Secrets

Only the public Supabase URL and publishable/anon key belong in frontend configuration. Service-role and secret keys must never be shipped to browsers.

Reporting

Before launch, publish a real support/security contact and complete an independent review of RLS policies and database constraints.