Security

Your compliance records, protected.

Superfood holds the records your business runs on: food safety checks, labels, specifications, orders and audits. Security is designed into how the platform is built, not bolted on afterwards. This page explains, in plain language, how your data is stored, protected, backed up and returned to you.

Infrastructure

Where your data lives

Superfood runs on established, security-focused cloud infrastructure rather than servers we rack ourselves.

Railway logo

Application

The Superfood application runs on Railway's managed cloud platform.

Supabase logo

Database

Your records live in a PostgreSQL database managed by Supabase, running on AWS infrastructure.

Cloudflare logo

Network

All traffic is fronted by Cloudflare, which shields the platform against attacks before requests reach us.

Every connection to Superfood is encrypted in transit with HTTPS (TLS), and your data is encrypted at rest by the database provider.

Provider security

Supabase logoOur database provider's security

The database layer is operated by Supabase, whose platform is independently audited and certified. Supabase publishes that its platform maintains:

  • SOC 2 Type 2 attestation
  • ISO 27001 certification
  • Encryption everywhere: AES-256 at rest and TLS in transit
  • Regular external penetration testing and continuous vulnerability scanning
  • Protection against DDoS and brute-force attacks

The certifications above are held by Supabase Inc. for its platform, on which Superfood's database runs. Full details are published at supabase.com/security.

Access

How access is controlled

Access to your account follows one principle: the server decides, never the browser.

  • Sign-in without passwords

    People sign in with a one-time email code or their Google account. Codes are rate limited and expire quickly, and sessions are carried in signed, httpOnly cookies.

  • Tenant isolation, enforced server-side

    Every request is pinned to the signed-in company on our servers. One customer's records are never reachable from another customer's account.

  • A locked-down database

    The database denies all direct access by default. Nothing but our own application servers can read or write your records.

  • Roles and permissions

    Custom roles control what each person can see and do, module by module and section by section. Transferring the account owner requires an emailed confirmation code, and QA sign-off gates critical records.

  • PIN-protected kiosks

    Factory-floor stations unlock with a PIN and lock out automatically after repeated failed attempts.

  • Share links you control

    Public links use long, unguessable tokens, can carry their own PIN, and stop working the moment you revoke them.

Accountability

Every change is on the record

Compliance software is only as good as its audit trail. Superfood records changes as a matter of course.

  • Amendment registers

    Forms, documents, labels and records log every change server-side: who made it, when, and what changed. The application cannot skip the log.

  • Version history with restore

    Documents, forms, label designs and reports keep numbered versions. Any version can be restored, and restoring is itself recorded.

  • Archive over delete

    Wherever possible, records are archived or snapshotted rather than hard-deleted, so history stays recoverable.

  • Accountable support access

    Superfood support access is limited to a small number of named staff, and every support sign-in to a customer account is logged.

Resilience

Backups and recovery

The database is backed up automatically every day by Supabase, with backups held separately from the live database. If something goes wrong, records can be restored through the provider's recovery tooling.

Rebuildable by design

The application itself is fully version-controlled and can be redeployed from source at any time. Code and data are recoverable independently of each other.

A natural second copy

For companies syncing master data from tools like Unleashed, MRPeasy or Xero, that data also continues to live in the source system.

Unleashed logoMRPeasy logoXero logo

No lock-in

Your data is yours

You should never need to ask permission to get your own records back. Superfood is built so you can take a complete copy of your data yourself, at any time.

Full export, self-serve

Company settings includes Export your data: one ZIP with a folder per feature and a CSV per table. No support ticket required.

Exports on every page

Registers, reports, planners and lists export to CSV, Excel or PDF wherever you work.

Leaving is respected

If you leave, you can export everything in full first, and we delete your data on request.

Third parties

Payments, email and AI

Where Superfood relies on outside services, we pick established providers and keep sensitive data out of our own systems.

Stripe logo

Payments

Card details never touch our servers. Billing runs through Stripe, and you manage your subscription in Stripe's own secure billing portal.

Gmail logoTwilio logo

Email and SMS

Emails send through the Gmail API and text messages through Twilio, both over encrypted connections.

Anthropic logo

AI features

AI features run on Anthropic's Claude API, which does not train its models on your data. Compliance-critical logic is deterministic code: AI is limited to suggestions and drafting that a person reviews.

Contact

Questions or concerns?

If you believe you have found a security vulnerability, or have questions about how your data is handled, contact us and we will respond promptly. You can check the live health of the platform at status.superfoodapps.com at any time.

[email protected]
v9.18