Current status
This repository provides a production-ready architecture, not a certification. A dedicated production backend and independent security review are required before real financial data is accepted.
Security controls included
- Cookie-based Supabase SSR authentication.
- PostgreSQL Row Level Security policies for user-owned businesses and records.
- Security headers, secret scanning, CodeQL and dependency updates.
- Audit log and data-deletion schema.
- No service-role keys exposed to client code.
Responsible disclosure
Do not open a public issue for a vulnerability. Contact the project owner privately through GitHub Security Advisories.