Security and governance
An overview of the controls the Comlytix platform and implementation approach are designed to support.
Role-based access
Implementations can separate views and actions by role, responsibility, organisation, branch and workflow state, with least-privilege access defined before production release.
Operational traceability
Records can retain user, timestamp, source event, reason, approval and resulting instruction associated with material workflow changes.
System boundaries
Integration design identifies authoritative sources, data ownership, read and write permissions, credential handling and failure behaviour.
Data protection
Sensitive credentials must remain server-side. Data collection should be minimised, encrypted in transit and protected according to classification and deployment requirements.
Secure delivery
Implementation proceeds through bounded scope, separated environments, acceptance criteria, change control, monitored deployment and rollback planning.
Supabase contact endpoint
The included contact architecture uses a server-side Edge Function, origin allow-list, validation, a honeypot and a database table that denies direct anonymous access. Follow SUPABASE-SETUP.md before enabling the form.
No certification claim
This website does not claim a specific security certification or compliance status. Formal obligations must be verified against the agreed production architecture, controls and contract.