Platform security

The platform runs on providers with SOC 2 Type 2 audits, encrypts data in transit and at rest, and separates each company's information at the database level.

Summary

The data customers upload (formulas, raw materials, consumption, invoices and reports) is protected in four layers:

  • Certified infrastructure. The database and files live in Supabase; the application runs on Vercel. Both operate under SOC 2 Type 2 controls audited every year by independent third parties.
  • Verified identity. Only registered users get in, with email and password or with their Google or Microsoft account.
  • Isolation between companies. Every database query goes through Row Level Security rules: a user can only read and change their own company's data.
  • Controlled changes. No change reaches production without review and approval by the technical lead.

Architecture and data location

Customer data is stored in Supabase; the application that processes it runs on Vercel. Every connection is encrypted over HTTPS.

ComponentProviderLocation
Database, files and sign-inSupabase (on AWS)[To be confirmed: São Paulo, Brazil]
Application and server functionsVercelWashington D.C., United States

Infrastructure: Supabase and Vercel

ProviderRoleCertificationsEncryption
SupabasePostgreSQL database, files and sign-inSOC 2 Type 2, audited annuallyIn transit and at rest
VercelRuns the web application and its server functionsSOC 2 Type 2; ISO 27001HTTPS on every connection; encryption at rest

What each certification covers. SOC 2 Type 2 is an independent auditor's report verifying, over a period, that security, availability and confidentiality controls work. ISO 27001 certifies the information security management system.

Shared responsibility. Supabase and Vercel protect the infrastructure: servers, network, operating system, backups and monitoring. Coralia is responsible for how the application uses it: who gets access, to which data and with which permissions.

Access to the platform

  • Sign-in. With email and password, or with a corporate Google or Microsoft account. Authentication is handled by Supabase Auth: the platform never stores readable passwords.
  • Sessions. The session travels in secure cookies and is renewed with short-lived tokens.
  • Invitation only. Each company's admin invites every person by email.
  • Coralia consultants. They have a separate role to review and certify emission factors, assigned on the server: users cannot grant it to themselves.
  • API access. Integrations use each company's own keys. The platform stores only a cryptographic fingerprint (SHA-256) of each key, and any key can be revoked at any time.
RoleViewUpload and editManage users
AdminYesYesYes
EditorYesYesNo
ReaderYesNoNo

Data isolation between companies

  • Row Level Security. Tables holding customer data have row-level security enabled, with rules that limit every read and write to the user's company.
  • Defense in depth. Even if an application bug asked for another company's data, the database would refuse it.
  • Files. Invoices, delivery notes and evidence are kept in private storage. To view them, the platform creates a signed link that expires after 5 minutes.
  • Server keys. Fully privileged credentials live only on the server, as encrypted environment variables, and never reach the browser.
  • Report integrity. When a consultant certifies a report, the platform stores its SHA-256 fingerprint. Anyone can check on the public verification page that the file they received is identical to the one that was signed.

Artificial intelligence and other providers

The platform uses the Anthropic API (Claude) to read documents and assist with calculations. Anthropic does not train models on data sent through the API and deletes it from its systems within 30 days, except content flagged for violating its usage policy. Values in a certified report are reviewed by a Coralia consultant.

ProviderPurposeData received
SupabaseDatabase, files and sign-inAll platform data
VercelRunning the applicationEach request's data while it is processed
AnthropicDocument reading and AI assistantDocuments and questions the user sends to the AI
ResendSending emailsRecipient email and notice content
Mercado PagoPaymentsPayment data; card details never pass through the platform
Google and MicrosoftCorporate sign-in and Google Calendar, if the user turns it onAccount name and email; events in the connected calendar

Secure development and change management

  • Protected main branch. Every change goes through a pull request that the technical lead reviews and approves.
  • Traceable deployments. Each published version is recorded with its author and date.
  • Production isolated from development. Each developer works against their own test database; real customer data is never used for development.
  • Versioned database changes. Every change to structure or access rules is a numbered migration reviewed together with the code.
  • Secrets out of the code. Keys and credentials live in encrypted environment variables, never in the repository.

Backups and continuity

  • Daily backup. The database is backed up automatically every day and can be restored to any of the last [7] days. [To be confirmed: Supabase plan.]
  • Files. Uploaded files are stored separately in Supabase Storage.
  • Availability. Vercel publishes every version immutably: if a new version fails, the previous one is restored within minutes.
  • Incident response. If an incident compromises a customer's data, Coralia notifies the designated contact within [72] hours of detecting it, with its scope and the measures taken.