Open navigation

Security

Trust starts with clear boundaries.

SupportMesh is built around explicit workspace, role, client, and internal-operation boundaries. This page describes implemented controls without claiming certifications the product has not earned.

Explicit boundaries

One support story. Different authorized views.

Public client communication and internal operating detail stay separated while both remain connected to the same workspace record.

01

Workspace isolation at the data layer

Application-facing data uses row-level security and workspace-aware authorization checks to keep organizations isolated.

02

Role and audience boundaries

Internal notes, operational records, and client-safe views are separated by explicit roles and server-side access checks.

03

Private file delivery

Attachments use private storage and controlled download paths rather than public object URLs.

04

Protected operational surfaces

Webhook verification, API-key hashing, audit records, and controlled worker endpoints protect integration surfaces.

What this means

Internal work stays internal.

Client-safe experiences

Portal users see approved requests, replies, estimates, releases, downloads, and knowledge for their client organization.

Controlled writes

Sensitive membership and operational changes use validated server or database operations instead of broad direct table writes.

Private attachments

File access is authorized before a controlled download is produced; storage objects are not public by default.

Platform boundary

Platform administration can manage workspace operations without automatically granting access to all future customer content.

Current assurance scope: SupportMesh does not currently claim SOC 2, ISO 27001, HIPAA, or third-party penetration-test certification on this site.

Your next request

Evaluate the workflow with its boundaries in view.

Review the product flow, technical documentation, and access boundaries before starting an evaluation.