Security

Security and tenant isolation

Controls for organization data, authentication, auditability, delivery, and safe integration behavior.

Access controls

Passwordless session tokens are signed, HTTP-only, same-site, and secure in production. Every organization-owned query includes an organization predicate, and PostgreSQL row-level security provides defense in depth.

Application security

  • Origin checks and CSRF-resistant same-site flows
  • Rate-limit integration points and no-store account responses
  • Server-only secrets with startup validation
  • Content Security Policy and restrictive browser permissions
  • Webhook signature verification and idempotent event storage

Operations

Source failures, stale feeds, schema warnings, missing evidence, date anomalies, delivery retries, bounces, and dead letters feed a protected health endpoint and daily summary.

Report an issue

Security reports: security@regchangenow.com. Do not include live credentials or confidential customer data in an initial message.