FynScale OS
Security
What FynScale OS does today to keep a firm’s work, and its clients’ information, with the right people.
Signing in
A firm sets which roles must sign in with a second factor, and the owner always must. The server checks it on every protected request, not only on the screen.
Who sees what
Access rules live in the database as row-level security, so each login reads only what its role allows: a client sees its own portal and the work released to it. A new table cannot ship without its own access rules: the build checks every new database change.
A record of what happened
Each client document keeps its history: who uploaded it and when, and every later move, rename or delete. An attempt to open something a login may not reach is logged as a fault for the owner to review.
In the browser
Every page is served over HTTPS with a content security policy that names the only places it may load from, and no other site can frame it.
Where it runs
The app runs on Vercel. Its database, sign-in and file storage run on Supabase.
Questions about security? Write to stephen@fynscale.com.