Security overview
Protection designed around department boundaries
RigCheck uses layered account, authorization, storage, records, and audit controls. This page describes current design and does not claim a third-party certification.
Identity and sessions
Supabase provides password authentication, verified email, recovery, and secure sessions. Protected requests obtain the current identity from the authentication provider instead of trusting editable browser identity fields. Rate limits reduce automated abuse.
Department authorization
Server-side checks require active membership for every protected department read and change. Administrative actions require an administrator or owner role; owner-only actions are checked separately. Department ownership transfers require a current-owner nomination and acceptance by the exact joined administrator. A browser-supplied department ID does not grant access.
Record integrity and retention
Completed reports preserve a snapshot of the rig, checklist version, providers, answers, and notes. Later configuration changes do not rewrite the report. Archiving is reversible preservation. Standard permanent disposal requires owner authority, an elapsed approved schedule, and no legal hold. A verified app-owner override for false test records requires department ownership, exact typed confirmation, and audit logging; it cannot bypass a legal hold or supply legal authority.
Storage and transmission
Connections use HTTPS. Operational records use Cloudflare D1. Profile photos are processed before storage in a private Cloudflare R2 bucket and served only after an authorized relationship is checked. Secrets are stored as server runtime settings and are not shipped to browsers or committed to source.
Vendors, payments, and backups
Cloudflare, Supabase, Resend, and Stripe provide infrastructure under their own security programs. Stripe handles payment details when billing is enabled. Department data exports provide portability, but customers should maintain any independent backups required by policy or law.
Monitoring and incident response
RigCheck uses service logs, rate controls, and audit events to support troubleshooting and investigation. Suspected security incidents are assessed, contained, remediated, and documented as appropriate. Notice will be provided to affected organizations or individuals when required by applicable law and available facts.
Customer responsibilities
Departments must maintain accurate access lists, protect devices and credentials, configure legal holds and retention authority correctly, train users not to enter patient information, and promptly report suspicious activity. No online service can guarantee absolute security.
Report a concern
Submit a security or access concern without passwords, patient information, exploit code, or sensitive evidence. RigCheck will arrange a safer channel if technical material is needed.