Security
Summary page — link your trust center, SOC2, and pentest schedule here as they go live.
- API keys stored as SHA-256 hashes; raw keys shown once at creation.
- Service-role data access stays server-side; browser clients use Supabase RLS.
- Browser workloads run on isolated workers — not inside serverless API routes.