Auth and access boundaries
Supabase-backed authentication with protected app routes and user-scoped API access checks.
Case Keeper
Security
We prioritize practical controls across authentication, origin boundaries, and billing integrations to reduce operational risk.
Supabase-backed authentication with protected app routes and user-scoped API access checks.
Worker origin allowlists and same-origin web proxy enforcement for sensitive API pathways.
Stripe webhook signature validation and idempotent subscription update handling.
Structured cutover runbook, parity checklist evidence, and rollback thresholds for release control.
Report security issues to security@case-keeper.com. Include reproducible steps and impact notes where possible.