Retainr

Application controls

Security, stated plainly.

These are controls enforced by the Retainr application. They are not a certification or a promise of absolute security.

Tenant isolation
PostgreSQL row-level security constrains access to tenant data, with isolation checks covering cross-tenant and anonymous access.
Server-validated sessions
Protected application pages validate the current user with Supabase Auth on the server before using the session.
Controlled document access
Finalized document bytes stay unavailable until a controlled processor records clean scan evidence bound to that immutable file version. Downloads use time-limited signed URLs.
Stronger checks for privileged actions
Platform administration and designated sensitive tenant actions enforce a verified AAL2 multi-factor authentication session.

Health-data use

Retainr does not claim HIPAA compliance and does not offer a business associate agreement. Do not use Retainr where your obligations require either.

Questions or a security concern? Contact support.