How we build securely

We build apps on Supabase, for the database and sign-in, and Vercel, for hosting. Both are established, managed platforms with independently audited security programs. Security is still shared: the platforms protect their infrastructure, and how an app is configured, who can see what, and how it is run are decided for each project. We match those decisions to what your project handles and agree them with you before launch. AI tools help us build faster; they don't replace the judgment of the people accountable for the work.

The platforms underneath

Supabase

SOC 2 Type II and ISO 27001. Data is encrypted at rest (AES-256) and in transit (TLS). Supabase security

Vercel

SOC 2 Type II for security, confidentiality and availability, and ISO 27001:2022. Data is encrypted at rest (AES-256) and in transit (TLS 1.3). Vercel security and compliance

SOC 2 Type II is an independent auditor’s report on whether a company’s security controls actually worked over a period of months, not just on one day. ISO 27001 is an international standard for running an information security program, certified by an accredited auditor.

These are the vendors’ credentials. They are not certifications of Teveyo, or of any app we build on their platforms.

Who’s responsible for what

Supabase and Vercel both publish a shared responsibility model. They secure the parts they run: the data centers, networks and servers, and the encryption of the data they store.

The app built on top is the customer’s side of that line, which in practice means ours and yours together: who can sign in, what each person can see, where secrets are kept, what gets logged, and how changes are released. Those choices are covered below, and they’re settled for each project before launch.

The details

Access and data isolation

Supabase runs on Postgres with row level security, so every request can be limited to the records the signed-in person is allowed to see. Before launch we agree, for each project: which roles exist and what each one can see, how staff sign in (including whether multi-factor sign-in is required), and that keys able to bypass access rules stay on the server, never in the browser.

How we build, including with AI

We use AI coding assistants to write and test code faster. They work inside the same process as everything else: changes are tracked in version control, and Vercel can show each change at its own preview address before it goes live. How changes are reviewed and released, and whether any client data or code may be shared with AI tools, are agreed with you before work starts.

Data protection and operations

Both platforms encrypt data at rest and in transit, and Supabase runs the database backups. How long backups are kept depends on the plan, so the plan is chosen with your recovery needs in mind. Where secrets such as API keys live, what gets logged, and who is alerted when something goes wrong are agreed for each project before launch.

Health data, personal data and payments

Health data (HIPAA). Both platforms can support HIPAA workloads, but only with a signed Business Associate Agreement (BAA), an eligible plan (Supabase Team or Enterprise; Vercel Pro with its HIPAA add-on, or Enterprise) and additional configuration. If your app will handle protected health information, we plan for that from the start.

Personal data (GDPR and similar laws). No platform can certify an app as compliant. It depends on what you collect, why, how long you keep it, and the agreements in place with every provider that processes it.

Payments. Card details should go straight to a payment processor such as Stripe, through its own form, so they never touch your app’s database. This is the pattern Vercel recommends for PCI DSS.

Sources and further review

The vendors share their full audit reports through their own trust centers and dashboards; access depends on the plan. If your organization needs a security questionnaire answered or wants to review a project’s setup, get in touch.

Start with the audit.

A 60-minute conversation to find your biggest opportunities.

Book a workflow audit →

No pressure. Just possibilities.

Sun rising over hills, with a road winding toward it Hand-drawn rays rotate slowly around a stationary sun, passing behind the hills.

A smoother
tomorrow
is possible

Book a workflow audit

Tell us what's eating your week.

A 60-minute conversation to find your biggest opportunities. We'll get back to you within one business day.