Current safeguards

Virali Security Overview

Status

This overview describes current safeguards. It is not a certification, audit report, or independent compliance claim.

Production isolation

Production uses isolated Render services, a production Supabase project, production Redis, production secrets, and the app.tryvirali.com domain. Staging and Reset resources must not be shared.

Authentication

Customer authentication is handled through Supabase Auth. Public signup remains disabled for the initial beta, and password-reset links use the production app origin.

Tenant isolation

Virali uses immutable organization identifiers, server-side authorization, tenant-aware database access, RLS policies, and scoped runtime roles that do not bypass RLS.

Secrets

Secrets are stored in provider-managed environment configuration and must not be committed, logged, exposed to browsers, or copied from staging or Reset except for the explicitly authorized Bright Data credential path.

Backups and recovery

Supabase provider backups are enabled according to provider status. Encrypted logical backups, offsite storage, and restore drills require the backup runbook and founder-approved encryption/offsite destination.

Monitoring

Health endpoints expose non-sensitive status and release correlation. Supplemental synthetic monitoring and provider alerts are documented in production monitoring runbooks.

Incident response

Incident runbooks cover outage, data isolation, secret exposure, provider failure, backup failure, and legal/privacy events. Support ownership and escalation windows require founder approval.

No unsupported claims

Virali does not claim SOC 2, HIPAA, GDPR certification, or other certification unless separately verified and approved.

Contact

Security contact: support@tryvirali.com. Support contact: support@tryvirali.com. Legal entity: Life Development LLC. Effective date: 7/18/2026.