Security
Last updated: October 2026
Security is the product, not a feature. Oxvenia is built with a security-first architecture designed for enterprise trust and audit readiness.
Data Isolation
All tenant data is isolated using Supabase PostgreSQL row-level security (RLS). No cross-tenant data exposure is tolerated, even in error paths. Organization-scoped tables enforce membership checks at the database layer.
Infrastructure
Production is hosted on Vercel with strict transport security headers. Database operations use encrypted connections. Secrets and API keys are managed through environment variables and never committed to source control.
Monitoring and Incident Response
Production errors and security events are captured through structured logging and monitoring. Incident response procedures include breach notification timelines aligned with applicable regulations. Audit logs are maintained for traceability.
Compliance
Oxvenia is designed to support SOC 2 Type I and Type II compliance for our customers. We continuously validate our controls and evidence collection to maintain the highest standards of trust.
Contact
To report a security vulnerability, contact us at support@oxvenia.com.