Security and product boundaries
MicroCD LabOps is designed around tenant isolation, least-privilege roles, private file storage, and auditable changes. These are engineering controls, not a certification or guarantee of regulatory suitability.
Organization isolation
Every tenant-owned database record includes an organization identifier. PostgreSQL row-level security verifies active membership, while server actions enforce role permissions. Cross-organization identifiers return a not-found response rather than exposing record existence.
Authentication and files
Supabase Auth manages sessions using server-readable secure cookies. Customer files use a private storage bucket and short-lived signed URLs. Service-role, Stripe, email, and AI keys remain server-only.
AI boundaries
AI drafting is disabled unless configured by an administrator. It uses only submitted context, marks generated sections as AI-assisted, and requires human review. It cannot approve reports or calculate pass/fail outcomes.
Not a regulated quality system
The launch product is not claimed to satisfy 21 CFR Part 11, ISO 13485, HIPAA, GDPR, FDA, electronic-signature, clinical validation, or any other regulated requirement. Customers must conduct their own risk, privacy, validation, and regulatory assessment.
Report a concern
Send security concerns to info@microcdlabs.com. Do not include secrets, patient information, or regulated production data in the first message.