Security

Security is part of the product boundary.

Onyx is designed so a public marketing surface, a signed-in analytics workspace, and owner-only growth controls do not all share the same level of access.

Tenant isolation

Production tables use PostgreSQL Row Level Security so authenticated users are restricted to authorized workspace data.

Server-only secrets

Privileged Supabase credentials are kept server-side and are not intentionally exposed through NEXT_PUBLIC environment variables or client bundles.

Minimal public surfaces

Public share pages expose only the metrics intentionally included in a share asset. Internal growth and owner controls remain restricted.

Source-controlled migrations

Database changes are represented in repository migrations so schema and security rules can be reviewed and reproduced.

Account-scoped access

Workspace membership is created at account provisioning and used to scope analytics imports and related records.

This page describes current design controls and is not a certification, penetration-test report, or guarantee that software can never contain a vulnerability.