Current safeguards
Virali Security Overview
Status
This overview describes current safeguards. It is not a certification, audit report, or independent compliance claim.
Production isolation
Production uses isolated Render services, a production Supabase project, production Redis, production secrets, and the app.tryvirali.com domain. Staging and Reset resources must not be shared.
Authentication
Customer authentication is handled through Supabase Auth. Public signup remains disabled for the initial beta, and password-reset links use the production app origin.
Tenant isolation
Virali uses immutable organization identifiers, server-side authorization, tenant-aware database access, RLS policies, and scoped runtime roles that do not bypass RLS.
Secrets
Secrets are stored in provider-managed environment configuration and must not be committed, logged, exposed to browsers, or copied from staging or Reset except for the explicitly authorized Bright Data credential path.
Backups and recovery
Supabase provider backups are enabled according to provider status. Encrypted logical backups, offsite storage, and restore drills require the backup runbook and founder-approved encryption/offsite destination.
Monitoring
Health endpoints expose non-sensitive status and release correlation. Supplemental synthetic monitoring and provider alerts are documented in production monitoring runbooks.
Incident response
Incident runbooks cover outage, data isolation, secret exposure, provider failure, backup failure, and legal/privacy events. Support ownership and escalation windows require founder approval.
No unsupported claims
Virali does not claim SOC 2, HIPAA, GDPR certification, or other certification unless separately verified and approved.
Contact
Security contact: support@tryvirali.com. Support contact: support@tryvirali.com. Legal entity: Life Development LLC. Effective date: 7/18/2026.