Account authentication
CrafPrint currently integrates Supabase Auth for sign-in and password recovery. Application API requests verify the signed-in user before allowing authenticated operations.
CrafPrint Security
Account and business information deserve careful handling. Security is part of how CrafPrint is designed, and an ongoing responsibility as the platform develops.
The points below distinguish the current implementation from deployment requirements and planned capabilities.
CrafPrint currently integrates Supabase Auth for sign-in and password recovery. Application API requests verify the signed-in user before allowing authenticated operations.
CrafPrint is designed around business workspaces. The current implementation includes business-membership checks and business-scoped requests. Production data separation is still being reviewed and verified.
Access should match the account and its permitted role. That principle guides the platform; the complete team invitation and permission experience remains under development.
HTTPS is a requirement for the intended production websites and application. Hosting configuration and secure-connection checks are part of release readiness; a live deployment has not been verified here.
Supabase is part of the current authentication and data-services architecture. Configuration, business access boundaries, and production readiness continue to require careful review.
Stripe is the intended subscription-payment provider. The integration is not yet active. The planned provider-handled checkout avoids the need for CrafPrint to collect or directly store full payment-card details.
Passwords & access
An ongoing responsibility
Security work continues as features, infrastructure, and business needs change. CrafPrint's approach includes reviewing access boundaries and configuration as the platform moves toward production.
No system can promise perfect security. We do not present planned controls or unfinished verification as completed assurance.
Email contact@crafprint.com and include “Security concern” in the subject. Describe what you noticed without sending passwords, payment-card information, or other unnecessary sensitive data.
Email a Security Concern