Built to be trusted

Your data, defended.

Servato is built on Supabase with row-level security, nightly encrypted backups, and the same operational discipline used by enterprise SaaS — without the enterprise price tag.

Encryption everywhere

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Secrets and API keys are stored in a managed vault, never in source control.

Nightly backups

Every workspace is backed up nightly to a private storage bucket. Org admins can restore any of the last 30 nightly snapshots from Settings → Backups.

Least-privilege access

Role-based permissions (owner, admin, manager, crew) plus per-feature gates. Only platform admins can access cross-org data, and every action is logged.

Row-Level Security on every table

Postgres RLS policies enforce workspace isolation at the database layer. A stolen anon key cannot read or write another organization’s rows.

Audit trails

Activity logs capture sign-ins, destructive actions, permission denials, referral events, and data exports. Platform admins can review the full history.

Incident response

We monitor errors and uptime continuously. If something breaks, our public status page shows it in real time and we contact affected admins within 72 hours.

Permissions you can test before you change them

Custom roles with per-feature gates, a permission simulator (pick a role, pick a screen, see exactly what they'd see), and an access-request inbox — staff ask from the locked screen, the owner approves or declines.

Session control

Each member's active device is listed with its last activity. Workspace admins can force-sign-out any session (it takes effect within a minute), and members active from several devices at once are flagged — the usual sign of a shared login.

Your workspace stays yours

Transfer ownership to a new owner in a few clicks — no support ticket — and run more than one business as separate workspaces with their own data, team, and billing.

Found a vulnerability?

Responsible disclosure is welcomed. We respond to every report within 2 business days.

Prefer e-mail or a machine-readable policy? Our disclosure details are published at security.txt