Security

Security and governance

Demandory is designed around company and product isolation, explicit permissions, controlled external actions, and evidence that can be reviewed during implementation.

Effective 28 July 2026

Identity and tenant isolation

Customer sessions use Supabase authentication and active company and product memberships. Internal operations are separately protected. A hostname, cookie, or client-supplied company identifier is never sufficient to authorize data access.

Application and data controls

  • Tenant-aware row-level security and product-scoped background work.
  • Role and capability checks for approval, publishing, integrations, and administration.
  • Signed and idempotent payment webhooks.
  • Audit events for important workspace and commercial changes.
  • Secrets held outside source control and provided only to the workloads that need them.

Human-review safeguard

Content remains review-gated. Advertising remains in zero-budget shadow mode unless a separately authorized commercial change enables live spend.

Security enquiries

Security and due-diligence requests may be sent to [email protected].