Trust
Security claims tied to implemented controls.
Danur authenticates users with Supabase Auth. Its API enforces organization membership, project access, and role permissions. Source documents use private storage mediated by the API, and important lifecycle and team actions retain attributable history.
- Browser and API responses use repository-defined security headers.
- Service-role storage credentials remain server-side.
- Logs are designed to exclude bearer tokens and customer document content.
- No certification or independent assurance claim is made on this page.
Operational and provider controls still require continuing release evidence and independent verification.