Identity and access
Cloud workspaces require Supabase authentication. Private access is decided by server-controlled database state, not editable profile fields.
Open app Security
Caliboard treats authentication, authorization, database policy, and browser protections as separate safeguards.
Cloud workspaces require Supabase authentication. Private access is decided by server-controlled database state, not editable profile fields.
Row-level security scopes boards and workspace data to authorized users and collaborators. Sensitive allowlists are not exposed through public schemas.
Private routes are excluded from indexing and receive restrictive framing, content-type, referrer, permissions, and Content Security Policy headers.
Analytics are opt-in, use a strict event/property allowlist, and exclude session replay, automatic capture, board content, titles, email addresses, and tokens.
Please do not include secrets, personal data, or exploit details in a public issue. Use the private security contact published with the repository or deployment.