Organisation isolation
Every company, assessment and recommendation is tied to an organisation, and access is checked per request instead of assumed from the UI.
AI-CRF Monitor deliberately separates data access, privileged operations and scoring logic. The frontend stays static, while security boundaries live in database policies and a small number of focused backend functions.
Every company, assessment and recommendation is tied to an organisation, and access is checked per request instead of assumed from the UI.
Supabase RLS is the access-control boundary. Client-side route guards improve usability but are not the authority for entitlements or data access.
Only Stripe, invitation and selected administrative operations use Cloudflare Pages Functions with server-held secrets.
Financial inputs are not sent to an LLM to calculate scores, fill missing values, rank priorities or improvise recommendations.
The product requests only the data required by the documented score model and the resulting audit trail.
Each assessment stores the formula version, input snapshot, derived metrics and triggered recommendation set.
The intended deployment path uses HTTPS through Cloudflare and Supabase, without claiming certifications or residency guarantees that have not been verified.
No digital system can promise absolute security. Risk is reduced through conservative design, testing and limited privilege, not marketing language.
Start on Free
Create your first company, enter the key financial values and receive a reproducible assessment.