Skip to content
SECURITY MODEL

Security here comes from boundaries, not from inflated promises.

AI-CRF Monitor deliberately separates data access, privileged operations and scoring logic. The frontend stays static, while security boundaries live in database policies and a small number of focused backend functions.

Organisation isolation

Every company, assessment and recommendation is tied to an organisation, and access is checked per request instead of assumed from the UI.

Row Level Security

Supabase RLS is the access-control boundary. Client-side route guards improve usability but are not the authority for entitlements or data access.

Minimal privileged backend

Only Stripe, invitation and selected administrative operations use Cloudflare Pages Functions with server-held secrets.

No generative-AI scoring

Financial inputs are not sent to an LLM to calculate scores, fill missing values, rank priorities or improvise recommendations.

Data minimisation

The product requests only the data required by the documented score model and the resulting audit trail.

Auditability

Each assessment stores the formula version, input snapshot, derived metrics and triggered recommendation set.

Transport and hosting

The intended deployment path uses HTTPS through Cloudflare and Supabase, without claiming certifications or residency guarantees that have not been verified.

Honest limitations

No digital system can promise absolute security. Risk is reduced through conservative design, testing and limited privilege, not marketing language.

Start on Free

Start with a defensible baseline.

Create your first company, enter the key financial values and receive a reproducible assessment.

Create a free account