Trust Center

How the product handles safety data and operational trust

A concise account of the controls and service boundaries implemented in HSE Dashboard today.

Pre-launch review status. This page describes current product behavior and is prepared for professional legal review. It is not final, legally approved wording.

Security and access model

Accounts use email and password authentication through Better Auth. Email verification is required, optional authenticator-app MFA is available, and authenticated sessions use signed, HTTP-only cookies. Tenant and role checks run on the server for protected data and actions.

Application data is stored in PostgreSQL. The deployed runtime uses a restricted database role, while the Supabase Data API is disabled for application data. These are implemented controls, not a claim of an external security certification.

Data handling and ownership

The product distinguishes person-owned account data from organization-owned HSE records. Organization records remain with the organization when a member account is removed; person-owned Professional Passport data follows the person's account. Uploaded source documents are kept in private object storage and served through authenticated, authorization-checked application routes.

HSE records can include incident descriptions, findings, corrective actions, evidence and occupational-health information. Access is limited by company, site and role boundaries. Occupational-health information may be sensitive, and customers should record only what is genuinely required for workplace health and safety purposes under their authority.

Limited first-party product analytics records coarse adoption milestones in the existing PostgreSQL application infrastructure. The analytics ledger does not intentionally store HSE record text, uploaded file contents, document names, AI prompts or answers, or occupational-health content.

Data export and deletion

A signed-in person can export an allowlisted copy of personal account data. Organization HSE records use report and Proof Pack export paths instead. Authentication secrets, session tokens, MFA secrets and reset tokens are excluded.

Account deletion requires password confirmation and is blocked while the account still owns a company. Person-owned content is deleted. Organization evidence remains with live account links removed or attribution changed to “Former user” where this can be done safely. Exact organization and backup retention periods are not approved or configured and require professional legal review before launch.

AI use and human accountability

When AI features are enabled and invoked, relevant prompts, selected HSE context, document text or images may be sent to the configured AI provider to draft, classify, summarize, recommend or assist retrieval. The deployment selects the provider through configuration; the production provider identity must be confirmed before launch.

AI output is assistance for review. Automated paths cannot silently approve, close, publish, make employment or medical-fitness decisions, or override high-impact HSE decisions. Later report lifecycle stages require an authorized person, and editing approved content returns it to human review. Occupational-health records are withheld from Assistant and Copilot context by default. Document-to-Work requires confirmation that an upload contains no occupational-health or medical information and blocks extraction into the Health register. Provider retention and model-training practices are not asserted here; they require confirmation against the applicable provider terms and deployment configuration before launch.

Service providers

  • Vercel hosts the web application and scheduled application jobs.
  • Supabase provides PostgreSQL and private object storage.
  • Cloudflare R2 is the independent object-backup target; matched restore verification remains a separate pre-launch gate.
  • Resend provides transactional email; final sender-domain verification remains a separate pre-launch gate.
  • Stripe provides hosted checkout, subscription billing and the billing portal.
  • Sentry provides operational error and reliability monitoring.

Which services receive data depends on the feature used and deployment configuration. This list does not disclose credentials, project identifiers, storage names or private endpoints. The production AI provider must be confirmed from deployment configuration before it is added to the public provider list.

Monitoring and reliability

Sentry is used for operational errors and selected sanitized security or delivery incidents. Audit monitoring excludes record summaries, audit metadata, actor identity, secrets and raw database errors. A company-scoped audit log records security-relevant, administrative and AI events. Monitoring is not an uptime guarantee.

Read the Privacy draft for data categories and processing boundaries, and the Terms draft for product responsibilities and subjects reserved for counsel. The Data Processing terms describe how HSEVIA processes customer-controlled content. Product questions can use Support, while vulnerabilities and suspected data-isolation incidents belong on the Security reporting page.