SoworaSOW · MULTIPLY · HARVEST · YIELDBack to Sowora

Security & privacy

Security, designed into the product

Sowora is built with security and privacy in mind. This page explains the controls reviewed as part of our pre-public-test security review and the areas we continue to verify as the product evolves.

Secure account access

Authentication, dashboard protection, confirmation flows and redirects were reviewed. Login and signup authentication errors were also changed to use generic messages rather than exposing raw authentication errors in redirect URLs.

User-scoped financial data

Supabase Row Level Security policies were reviewed across accounts, categories, transactions, financial profiles, expenses, credit cards and loans. Update policies also prevent ownership reassignment.

Protected PDF processing

The authenticated extraction endpoint checks the PDF extension and file signature, limits uploads to 25 MB, uses temporary processing directories, restricts the child process environment, limits extractor output and applies a 120-second timeout.

Extraction concurrency is limited to two processes per server process, with cleanup performed in a finalization path.

Controlled extraction results

Extracted data is bounded before downstream processing, including limits on transaction count, description length, raw source lines and diagnostic notes. These controls reduce the risk of oversized extraction results consuming excessive resources.

Secrets and environment protection

The security review found no service-role, admin or secret Supabase key references in the reviewed app, library or script code. Environment files are ignored by Git, with only the example environment file tracked.

Browser security headers

Baseline browser security headers are applied, including X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy.

Dependency and code checks

The review included TypeScript checking, a production build, dependency auditing and scans for dangerous runtime execution, HTML injection and exposed secret-key references. The reported dependency audit found zero vulnerabilities.

Redirect safety

Authentication confirmation redirects restrict the destination to permitted internal paths and reject external-style paths beginning with double slashes.

Security review

Security controls reviewed and strengthened

Sowora's security controls have been reviewed across authentication, database access, document processing, application configuration and dependency security. Identified hardening opportunities were addressed and verification checks were completed.

Security is an ongoing process. We continue to review and strengthen Sowora as the product evolves, with independent security testing planned as part of our security roadmap.