B
BizBrew

Security built in

BizBrew keeps each business's data separate, encrypts every connection and checks access on every request — on every plan, with no extra configuration.

Security is not an add-on

On a platform shared by many businesses, separating their data is the most important job. BizBrew is built around it, and you get the same protection on the free plan as on the Pro plan.

How we protect your data

Tenant isolation

Every record belongs to one business. Our backend filters every query by the business of the signed-in user. Direct database access is closed to users, and PostgreSQL row-level security is enabled on every table as an extra safeguard.

Proven authentication

Sign-up, sign-in, password recovery and sessions run on Supabase GoTrue with short-lived JWTs and automatic token refresh. Passwords are stored only as hashes.

Role-based access

Business owners and staff have separate roles, and staff access can be narrowed with permissions. The backend checks the caller's membership and role before it acts.

Encryption in transit

All traffic uses HTTPS. Custom domains receive TLS certificates automatically, so your customers always see a secure connection.

Audit logging

Significant actions — such as creating a business, verifying an account and administrative changes — are recorded with who did what and when, for review when you need it.

GDPR support

Data is separated per business, you can export your records, we sign a data processing agreement with you, and we publish our sub-processors.

How data isolation works

All businesses share one database, and every table carries a tenant ID. Isolation is enforced in the application on every request; database-level protections are an extra line of defence.

  1. Request arrives

    The business is identified from the domain or subdomain the request was sent to.

  2. Authentication and membership

    The backend verifies the user's session token, confirms the user belongs to that business and checks the user's role.

  3. Tenant-filtered queries

    Every database query the backend runs is filtered by that business's ID. Users cannot query the database directly, and row-level security on every table is an extra safeguard.

  4. Response returned

    Only that business's data is returned, over an encrypted HTTPS connection.

Ready to build on a secure foundation?

Start for free. No credit card required.