Platform security
The platform runs on providers with SOC 2 Type 2 audits, encrypts data in transit and at rest, and separates each company's information at the database level.
Summary
The data customers upload (formulas, raw materials, consumption, invoices and reports) is protected in four layers:
- Certified infrastructure. The database and files live in Supabase; the application runs on Vercel. Both operate under SOC 2 Type 2 controls audited every year by independent third parties.
- Verified identity. Only registered users get in, with email and password or with their Google or Microsoft account.
- Isolation between companies. Every database query goes through Row Level Security rules: a user can only read and change their own company's data.
- Controlled changes. No change reaches production without review and approval by the technical lead.
Architecture and data location
Customer data is stored in Supabase; the application that processes it runs on Vercel. Every connection is encrypted over HTTPS.
| Component | Provider | Location |
|---|---|---|
| Database, files and sign-in | Supabase (on AWS) | [To be confirmed: São Paulo, Brazil] |
| Application and server functions | Vercel | Washington D.C., United States |
Infrastructure: Supabase and Vercel
| Provider | Role | Certifications | Encryption |
|---|---|---|---|
| Supabase | PostgreSQL database, files and sign-in | SOC 2 Type 2, audited annually | In transit and at rest |
| Vercel | Runs the web application and its server functions | SOC 2 Type 2; ISO 27001 | HTTPS on every connection; encryption at rest |
What each certification covers. SOC 2 Type 2 is an independent auditor's report verifying, over a period, that security, availability and confidentiality controls work. ISO 27001 certifies the information security management system.
Shared responsibility. Supabase and Vercel protect the infrastructure: servers, network, operating system, backups and monitoring. Coralia is responsible for how the application uses it: who gets access, to which data and with which permissions.
Access to the platform
- Sign-in. With email and password, or with a corporate Google or Microsoft account. Authentication is handled by Supabase Auth: the platform never stores readable passwords.
- Sessions. The session travels in secure cookies and is renewed with short-lived tokens.
- Invitation only. Each company's admin invites every person by email.
- Coralia consultants. They have a separate role to review and certify emission factors, assigned on the server: users cannot grant it to themselves.
- API access. Integrations use each company's own keys. The platform stores only a cryptographic fingerprint (SHA-256) of each key, and any key can be revoked at any time.
| Role | View | Upload and edit | Manage users |
|---|---|---|---|
| Admin | Yes | Yes | Yes |
| Editor | Yes | Yes | No |
| Reader | Yes | No | No |
Data isolation between companies
- Row Level Security. Tables holding customer data have row-level security enabled, with rules that limit every read and write to the user's company.
- Defense in depth. Even if an application bug asked for another company's data, the database would refuse it.
- Files. Invoices, delivery notes and evidence are kept in private storage. To view them, the platform creates a signed link that expires after 5 minutes.
- Server keys. Fully privileged credentials live only on the server, as encrypted environment variables, and never reach the browser.
- Report integrity. When a consultant certifies a report, the platform stores its SHA-256 fingerprint. Anyone can check on the public verification page that the file they received is identical to the one that was signed.
Artificial intelligence and other providers
The platform uses the Anthropic API (Claude) to read documents and assist with calculations. Anthropic does not train models on data sent through the API and deletes it from its systems within 30 days, except content flagged for violating its usage policy. Values in a certified report are reviewed by a Coralia consultant.
| Provider | Purpose | Data received |
|---|---|---|
| Supabase | Database, files and sign-in | All platform data |
| Vercel | Running the application | Each request's data while it is processed |
| Anthropic | Document reading and AI assistant | Documents and questions the user sends to the AI |
| Resend | Sending emails | Recipient email and notice content |
| Mercado Pago | Payments | Payment data; card details never pass through the platform |
| Google and Microsoft | Corporate sign-in and Google Calendar, if the user turns it on | Account name and email; events in the connected calendar |
Secure development and change management
- Protected main branch. Every change goes through a pull request that the technical lead reviews and approves.
- Traceable deployments. Each published version is recorded with its author and date.
- Production isolated from development. Each developer works against their own test database; real customer data is never used for development.
- Versioned database changes. Every change to structure or access rules is a numbered migration reviewed together with the code.
- Secrets out of the code. Keys and credentials live in encrypted environment variables, never in the repository.
Backups and continuity
- Daily backup. The database is backed up automatically every day and can be restored to any of the last [7] days. [To be confirmed: Supabase plan.]
- Files. Uploaded files are stored separately in Supabase Storage.
- Availability. Vercel publishes every version immutably: if a new version fails, the previous one is restored within minutes.
- Incident response. If an incident compromises a customer's data, Coralia notifies the designated contact within [72] hours of detecting it, with its scope and the measures taken.