Security controls visible in the current codebase
This page describes implementation patterns found in Dashier’s repository. It is not a certification, independent audit, guarantee, or complete deployment security policy.
Sign-in
The current account flow uses Google OAuth through Supabase Auth; email/password sign-in is not implemented.
Tenant and membership scope
Organization, project, and source membership are resolved on server paths before records are exposed. The deployment and database policies must also be reviewed.
API keys
Keys are randomly generated; the application stores a SHA-256 hash rather than the raw key. Key scopes include read, write, and admin.
Request controls
Generated routes validate list-query shapes and record field values, enforce endpoint access modes, and apply configured rate limits.
Roles
System and custom roles are available. Route authorization checks project/source access and the configured role or API-key requirements.
Audit entries
The application writes audit rows for several record and administrative changes. This is not described as a complete SIEM or compliance log.
Operational facts that are not published
No independent security certification, penetration-test report, incident-response commitment, uptime SLA, backup/restore commitment, encryption configuration, or deployment-region statement has been supplied for this page. A source-code review does not verify production configuration. Contact support@dashier.app for questions about a specific deployment.
For safe API use, keep private keys on a server, use the narrowest key scope, configure endpoint policies deliberately, and test both allowed and denied requests. See the permissions guide.