Skip to content
Security information · updated 4 October 2026

Security controls visible in the current codebase

This page describes implementation patterns found in Dashier’s repository. It is not a certification, independent audit, guarantee, or complete deployment security policy.

Sign-in

The current account flow uses Google OAuth through Supabase Auth; email/password sign-in is not implemented.

Tenant and membership scope

Organization, project, and source membership are resolved on server paths before records are exposed. The deployment and database policies must also be reviewed.

API keys

Keys are randomly generated; the application stores a SHA-256 hash rather than the raw key. Key scopes include read, write, and admin.

Request controls

Generated routes validate list-query shapes and record field values, enforce endpoint access modes, and apply configured rate limits.

Roles

System and custom roles are available. Route authorization checks project/source access and the configured role or API-key requirements.

Audit entries

The application writes audit rows for several record and administrative changes. This is not described as a complete SIEM or compliance log.

Operational facts that are not published

No independent security certification, penetration-test report, incident-response commitment, uptime SLA, backup/restore commitment, encryption configuration, or deployment-region statement has been supplied for this page. A source-code review does not verify production configuration. Contact support@dashier.app for questions about a specific deployment.

For safe API use, keep private keys on a server, use the narrowest key scope, configure endpoint policies deliberately, and test both allowed and denied requests. See the permissions guide.