Security by design

Security evidence, before release.

See how mypage isolates projects, keeps credentials out of source, tests the browser flow, and binds approval to the exact artifact you publish.

Release gate9 checks
  • Secrets
  • Database access
  • Privileged RPC
  • Authentication
  • Browser storage
  • URL navigation
  • Connectors
  • Dependencies
  • Artifact scan

Review status and evidence stay bound to the exact artifact fingerprint.

Assurance boundary

Evidence over badges.

Every claim here is limited to a control we can explain and test today. We do not display SOC 2, ISO, data-residency, or blanket “never used for training” badges without a current contractual and operational record. Validate the provider and region configured for your deployment before placing regulated data in a project.

Product controls

Four boundaries stay visible in the workflow.

01

Identity and tenant boundaries

Owner, admin, editor, and viewer permissions are enforced by server-side project and workspace checks. Generated database starters declare their own role and row-policy boundary; a template never makes an anonymous admin promise.

02

Write-only project secrets

Provider credentials are submitted over an authenticated path, encrypted by the platform boundary, and cannot be read back from the workspace. They are omitted from generated source, logs, browser storage, and exports.

03

Fingerprint-bound publishing

A source scan produces a fingerprint. Publishing is fail-closed when critical or high findings remain, and activation is tied to the exact requested revision and its final artifact scan—not a different passing build.

04

Recovery and controlled deletion

Checkpoints protect source and supported project data, and restore creates a safety point first. Deletion enters a tombstoned pending state before scoped cleanup; ordinary application paths cannot bypass that lifecycle.

Security Center

Nine checks before a verified release.

Each check reports its stage, status, evidence, and next action. The server—not a hidden client toggle—enforces the publish decision.

  1. 01
    Secrets

    Scans source and the final build artifact for credential-shaped values.

  2. 02
    Database access

    Reviews row policies and project-scoped data boundaries.

  3. 03
    Privileged RPC

    Flags callable database capabilities that cross a user boundary.

  4. 04
    Authentication

    Flags unresolved authentication markers on privileged routes.

  5. 05
    Browser storage

    Finds sensitive data placed in durable browser storage.

  6. 06
    URL navigation

    Reviews redirect, iframe, and browser execution sinks.

  7. 07
    Connectors

    Flags unresolved connector markers that are not launch-ready.

  8. 08
    Dependencies

    Uses a platform-managed package and lockfile boundary; registry vulnerability review remains a release/CI responsibility.

  9. 09
    Artifact scan

    Re-scans the exact production bundle before it can be activated.

Data and providers

Know the shared-responsibility line.

What the platform controls

Workspace authorization, sandbox preparation, encrypted project-secret handling, release checks, revision activation, backups, and lifecycle cleanup.

What you control

The data entered into the generated app, final user roles and row policies, connector recipients, legal notices, retention requirements, and every finding you accept before release.

Potential subprocessors

A configured project may use Amazon Web Services, Supabase, Anthropic or Z.AI, plus only the payment, messaging, map, shipping, or business-data connector you select. The project launch checklist identifies those boundaries; provider setup is never implied by a template screenshot.

Preview limitations

A dated production subprocessor register, independent assurance report, public status history, formal incident SLA, and residency matrix are GA release gates—not claims made by this preview page.

Report a concern

Give us a reproducible path, never a live secret.

Include the affected route, expected boundary, observed result, and a safe proof of concept. Do not send credentials, personal data, or destructive payloads.