Open app

Security

Private workspaces with layered controls.

Caliboard treats authentication, authorization, database policy, and browser protections as separate safeguards.

Identity and access

Cloud workspaces require Supabase authentication. Private access is decided by server-controlled database state, not editable profile fields.

Data isolation

Row-level security scopes boards and workspace data to authorized users and collaborators. Sensitive allowlists are not exposed through public schemas.

Browser protections

Private routes are excluded from indexing and receive restrictive framing, content-type, referrer, permissions, and Content Security Policy headers.

Analytics boundaries

Analytics are opt-in, use a strict event/property allowlist, and exclude session replay, automatic capture, board content, titles, email addresses, and tokens.

Report a security issue

Please do not include secrets, personal data, or exploit details in a public issue. Use the private security contact published with the repository or deployment.