SECURITY & BUYER ASSURANCE

Trust begins with accurate claims.

RAQOZ publishes the controls that are verifiable today and leaves certifications, service levels and security assurances unclaimed until evidence exists.

Tenant separation

Organisation membership and permissions are enforced in the database; the browser cannot grant itself access.

Audit logging

Material workflow transitions emit immutable audit events. Corrections must create new evidence instead of rewriting history.

Private documents

Procurement attachments use organisation-scoped private storage policies; public branding assets are separated.

CURRENT VERIFIED SCOPE

Buyer-assurance answers tied to released controls.

Identity and access

Supabase Auth handles account authentication. Organisation membership, active status and permission checks remain enforced by database policy.

Tenant separation

Organisation-owned tables use forced row-level security and organisation-scoped workflow functions; the browser cannot grant itself cross-tenant access.

Private procurement documents

Procurement attachments use private, organisation-scoped storage policies. Public marketing assets are separated from tenant documents.

Attributable audit history

Material workflow transitions write actor and timestamp evidence to audit events that database triggers prevent from being updated or deleted.

Evidence packs and portability

Released workflows provide tenant-scoped transaction evidence, governed exports and SHA-256 manifests within the stated pack scope.

Security reporting

Suspected vulnerabilities can be reported privately to Cyclotron Technologies. Reports should contain minimum reproducible evidence and no passwords, tokens or customer documents.

RESPONSIBLE REPORTING

Report a suspected vulnerability privately.

Send the affected surface, reproduction steps, impact and minimum validation evidence. Do not send passwords, access tokens, bank details, personal data, procurement documents or production customer data.

Email the security report
Not asserted: RAQOZ does not currently claim SOC 2, ISO 27001 certification, completed penetration testing, a fixed RTO/RPO, guaranteed availability, universal data residency or zero data loss. Backup/PITR selection, restore rehearsal, production SMTP, approved migrations and signed-in release validation remain operational launch gates.