Secure authentication
Supabase Auth, PKCE OAuth, verified email flows, secure cookie sessions, and narrowly scoped Google identity permissions.
Tethi is designed to protect private workspace decisions and public customer conversations with practical layers of defense.
Supabase Auth, PKCE OAuth, verified email flows, secure cookie sessions, and narrowly scoped Google identity permissions.
Workspace roles, super-admin access, plan limits, and protected mutations are enforced on the server and backed by RLS.
Constrained relational data, tenant policies, soft deletion, controlled storage access, export controls, and recovery planning.
Strict validation, sanitization, CSP and security headers, rate limits, honeypots, file checks, and secret-safe configuration.
Administrative and destructive actions are recorded, Stripe events are idempotent, and moderation decisions remain traceable.
Provider readiness is monitored without revealing secrets. Security reports receive prompt, good-faith review.
Email security@tethi.com with a clear description, reproduction steps, and potential impact. Please avoid accessing other users’ data or disrupting the service.