Security
Security and governance
Demandory is designed around company and product isolation, explicit permissions, controlled external actions, and evidence that can be reviewed during implementation.
Effective 28 July 2026
Identity and tenant isolation
Customer sessions use Supabase authentication and active company and product memberships. Internal operations are separately protected. A hostname, cookie, or client-supplied company identifier is never sufficient to authorize data access.
Application and data controls
- Tenant-aware row-level security and product-scoped background work.
- Role and capability checks for approval, publishing, integrations, and administration.
- Signed and idempotent payment webhooks.
- Audit events for important workspace and commercial changes.
- Secrets held outside source control and provided only to the workloads that need them.
Human-review safeguard
Content remains review-gated. Advertising remains in zero-budget shadow mode unless a separately authorized commercial change enables live spend.
Security enquiries
Security and due-diligence requests may be sent to [email protected].