Row-level security restricts private records to authorised tenant users.
Security
Access control is a product feature.
PopUsIn keeps tenant boundaries, user roles and sensitive operations in the database and protected server functions.
Platform Owner, Platform Admin and tenant roles have different powers.
No service-role or secret database key is shipped in the website.
Customer actions use expiring, one-way hashed access tokens.
Users can enrol an authenticator app and owners can reset lost factors.
Responsible operation
Security stays under review.
Release checks cover row-level security, public data exposure, authentication routes, file access and database advisories. Provider connections receive their own test before activation.
Report a security concern
Do not include live passwords, payment details or unrelated personal data.
Email PopUsIn securely