Infrastructure & Protection
Security Policy & Responsible Disclosure
Last Updated: August 29, 2026
Security by Design: Tenant Isolation & Client-Side Privacy
SlipDesk applies defense-in-depth security principles across both its browser-native offline engine and cloud infrastructure. We protect your pricing models, profit margins, and retail relationships with strict multi-tenant isolation.
1. Data Architecture & Tenant Isolation
- Row Level Security (RLS): In our Supabase PostgreSQL cloud database, every table (
organizations,products,customers,orders,order_items,ledger) enforces strict Row Level Security policies. Queries execute only within the scope of the authenticated user'sorganization_id. - Local Storage Sandboxing: Offline browser data is strictly isolated within the origin boundary (
https://dealer-line.vercel.app) and cannot be accessed by other websites. - Encryption in Transit: All communications between client devices and cloud services require TLS 1.3 / HTTPS encryption.
2. Authentication & Passwords
- User passwords are never stored in plaintext; authentication uses standard industry password hashing (bcrypt) managed by Supabase Auth.
- JSON Web Tokens (JWTs) are cryptographically signed with asymmetric keys (JWKS) and expire automatically.
3. Responsible Vulnerability Disclosure Program
We welcome contributions from security researchers. If you discover a potential vulnerability in SlipDesk, please disclose it to us responsibly before making it public:
Disclosure Guidelines:
- Email detailed technical findings and reproduction steps to security@slipdesk.in or message our verified technical helpline.
- Do not access, modify, or delete data belonging to other wholesale accounts.
- Give our engineering team a reasonable window (minimum 14 business days) to investigate and patch the issue before public disclosure.
4. Security Contact
SlipDesk Security & Infrastructure Engineering
Email: security@slipdesk.in
WhatsApp Security Urgent Line: +91 9158915956