Enterprise
A digital workforce that clears procurement.
SSO and SCIM, 2FA, row-level security, an immutable audit log, DPA, EU data residency, and dedicated support — the controls regulated environments demand are built in, not retrofitted.
per law and executed agreement
Breach notification
verify with operator
On-Call
Enterprise controls in detail
Identity & access
Centralized provisioning and sign-in through your existing identity provider.
- Supabase Auth (email + password, magic link, OAuth, SAML, SCIM)
- TOTP 2FA (RFC 6238) required for owner/admin roles
- SAML 2.0 via @node-saml/node-saml — XML signature-wrapping protected
- SCIM 2.0 for Enterprise just-in-time provisioning
Authorization & roles
Fine-grained permissions enforced at the API and database layer.
- Seven built-in roles × resource-action policy matrix
- Workspace-scoped permissions enforced at API + DB layer
- Break-glass admin access requires two-person approval
Tenant isolation
Every customer row is workspace-scoped and protected by row-level security.
- Multi-tenant — workspace_id on every customer row
- Static migration audit: RLS enabled for all 149 workspace-scoped tables
- Storage bucket isolation: every object path is prefixed with workspace_id
- Cross-tenant defence-in-depth — code-layer guards + DB policies
Audit & traceability
Every privileged action lands immutably and hash-chained in the audit log.
- Immutable audit log (append-only, hash-chained) for every privileged action
- Five anomaly detectors: mass-delete, privilege-escalation, geo-anomaly, brute-force, off-hours-admin
- OpenTelemetry → OTLP export to customer-owned SIEM on Enterprise
- Sentry for error tracking, Langfuse for AI tracing
Encryption
Encryption at rest and in transit, with key rotation.
- AES-256-GCM application encryption for reviewed OAuth-token and secret surfaces
- TLS 1.2+ in transit; HSTS preload
- DPA signatures sealed with SHA-256 tamper-evidence hash
- Dual-key online rotation path; operating cadence is deployment-specific
Configurable infrastructure
Hosting, backup, and recovery regions are deployment-specific and require operator evidence.
- Vercel (EU edge) + Supabase (EU region) — production data never leaves the EU
- Daily encrypted DB backups + 7-day point-in-time recovery
- Cloudflare DDoS protection on every public edge
- WAF + per-workspace rate limits
EU data residency — verifiable, not just claimed
Production data is processed and stored in the EU. Our customer-data sub-processors are publicly listed — with location, purpose, and DPA status. Currently 11 of them are EU-based; every change is announced 30 days in advance.
Everything your procurement team needs
Pre-answered RFP questionnaire
Security and privacy questions answered up front — accelerates your procurement.
View RFP →Data processing agreement (DPA)
GDPR Art. 28 contract, electronically signed at first workspace provisioning.
Read the DPA →Service-level agreement
Availability and response commitments for production enterprise environments.
View SLA →Trust Center
Compliance status, sub-processors, security architecture, and the trust pack in one place.
Open Trust Center →Dedicated support
Enterprise customers get a named point of contact, prioritized response times, and guided onboarding for their digital workforce — from SSO setup to rolling out the first workflows.
P1 incidents are acknowledged within a short time; operations are monitored 24/7 through a follow-the-sun rotation.
Ready for the enterprise evaluation?
Talk to sales or request our pre-answered RFP questionnaire — we'll get you through procurement fast.