HoundBase
AboutSecurityPrivacy
Back to product

Trust

01About HoundBase02Privacy03Terms & conditions04Data processing05Subprocessors06Security

Updated 24 August 2026

Security at HoundBase

HoundBase is built so each dog-care business works inside its own workspace and so operational records are protected throughout the service.

Tenant separation

Customer workspaces are separated in the application and database access model. HoundBase maintains automated tenant-isolation coverage to detect attempts to read or modify records belonging to another workspace.

Authentication and access

  • User authentication is provided through Supabase Auth.
  • HoundBase requires strong passwords in its account flows.
  • Team access should be granted only to people who need it and removed promptly when no longer required.
  • Account-deletion testing includes global session revocation before Auth-user deletion and verification that the old refresh token can no longer create a session.
  • Supabase leaked-password protection is not currently enabled on the plan in use; this is tracked as a future defence-in-depth improvement rather than represented as active protection.

Database access controls

HoundBase uses row-level security and business-membership checks to limit records to the appropriate workspace. Privileged RLS helper functions are held in a private schema rather than exposed as public API functions. Current public application tables have RLS enabled.

Database access policies and foreign-key indexes are also checked with Supabase's security and performance advisors. The current Security Advisor reports no database/RLS finding beyond the Auth leaked-password-protection warning described above.

Application and infrastructure

  • Production hosting is provided through Vercel.
  • Database, authentication and storage infrastructure are provided through Supabase.
  • The active Supabase project uses eu-west-1 (Ireland) as its primary project region.
  • Application secrets are kept in managed environment variables rather than committed to the repository.
  • Traffic to the production site is served over HTTPS.
  • Security headers restrict framing, content-type sniffing and unnecessary browser permissions.

Testing

HoundBase maintains end-to-end coverage for core product workflows, including authenticated use and tenant isolation. Launch-readiness testing has also covered database export and cascade deletion, account session revocation and Auth deletion, and isolated database + Storage recovery.

Backups and recovery

HoundBase uses separate logical database and private-Storage backups because database backups do not contain the underlying Storage object bytes. On 24 August 2026 an isolated recovery drill restored the HoundBase database snapshot and all three Storage objects from the test backup; restored application-table counts matched the source snapshot.

Backups are kept outside the application repository and are subject to the retention and access controls described in the privacy and data-processing documentation.

Incident response

HoundBase maintains an internal incident-response procedure covering severity, containment, evidence preservation, credential/session revocation, recovery, customer communication and personal-data-breach assessment.

Responsible disclosure

If you believe you have found a security issue, do not access or alter data that does not belong to you. Send the report to ibzy1199@gmail.com with enough detail to reproduce or assess the issue. Security reports are handled directly by the HoundBase operator.

HoundBase

Operational clarity for people who care for dogs.

About HoundBasePrivacyTerms & conditionsData processingSubprocessorsSecurity

© 2026 HoundBase