Skip to content

Security

Last updated: October 2026

Security is the product, not a feature. Oxvenia is built with a security-first architecture designed for enterprise trust and audit readiness.

Data Isolation

All tenant data is isolated using Supabase PostgreSQL row-level security (RLS). No cross-tenant data exposure is tolerated, even in error paths. Organization-scoped tables enforce membership checks at the database layer.

Infrastructure

Production is hosted on Vercel with strict transport security headers. Database operations use encrypted connections. Secrets and API keys are managed through environment variables and never committed to source control.

Monitoring and Incident Response

Production errors and security events are captured through structured logging and monitoring. Incident response procedures include breach notification timelines aligned with applicable regulations. Audit logs are maintained for traceability.

Compliance

Oxvenia is designed to support SOC 2 Type I and Type II compliance for our customers. We continuously validate our controls and evidence collection to maintain the highest standards of trust.

Contact

To report a security vulnerability, contact us at support@oxvenia.com.