Your data, defended.
Servato is built on Supabase with row-level security, nightly encrypted backups, and the same operational discipline used by enterprise SaaS — without the enterprise price tag.
Encryption everywhere
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Secrets and API keys are stored in a managed vault, never in source control.
Nightly backups
Every workspace is backed up nightly to a private storage bucket, with point-in-time restore available to org admins from Settings → Backups.
Least-privilege access
Role-based permissions (owner, admin, manager, crew) plus per-feature gates. Only platform admins can access cross-org data, and every action is logged.
Row-Level Security on every table
Postgres RLS policies enforce workspace isolation at the database layer. A stolen anon key cannot read or write another organization’s rows.
Audit trails
Activity logs capture sign-ins, destructive actions, permission denials, referral events, and data exports. Platform admins can review the full history.
Incident response
We monitor errors and uptime continuously. If something breaks, our public status page shows it in real time and we contact affected admins within 24 hours.
Found a vulnerability?
Responsible disclosure is welcomed. We respond to every report within 2 business days.