Security
Security
Riera Studio uses layered application, database, storage and operational controls to protect company workspaces. Security is reviewed as the service and threat environment change.
Authentication and sessions
User authentication is provided through Supabase Auth. Private routes require an authenticated user, and the server also supports a signed, HTTP-only application session used by the established production login flow.
Session cookies use secure attributes in production. Logout and account deletion clear application and Supabase session cookies. Password changes use secure email reset links to the registered account email.
Company isolation and roles
Operational records are scoped to a company. Database Row Level Security, membership functions and server-side company and role checks are used to prevent cross-company access.
Owner, admin, manager, employee/member and viewer-style roles restrict available actions. Platform administration is protected separately and sensitive mutations require server-side platform-admin checks.
Documents and exports
Private documents are returned only through authorised server routes or protected storage access. Export routes authenticate the requester and restrict full workspace exports to active owners and administrators.
Downloads use private, no-store responses where appropriate. Secret keys, password hashes, session tokens and full payment card information are excluded from customer exports.
Secrets and privileged operations
Service-role database keys, Stripe secrets, webhook secrets and other credentials remain server-side and are configured through protected environment variables.
Privileged database functions are not executable by public, anonymous or normal authenticated roles. Payment, admin, email, document and external-provider actions are performed by server handlers with authentication and permission checks.
Payments
Stripe handles payment card entry and payment processing. Riera Studio stores customer, subscription and payment-status references needed to operate billing, not full card numbers or security codes.
Stripe webhook signatures must be verified before subscription state is changed. Customers manage payment methods and cancellation through the Stripe-hosted billing portal.
Logging, analytics and minimisation
Security and admin actions are logged where needed for investigation and accountability. Access to privacy requests, deletion records and platform administration is restricted.
Optional analytics is disabled before consent. Riera Studio disables PostHog automatic element capture and session recording and sends sanitised page paths without query strings.
Incident response
Suspected incidents are contained, investigated and documented under the internal incident-response plan. Credentials and sessions are revoked where required, provider evidence is preserved and affected company isolation is retested.
Confirmed customer-data breaches are notified to the relevant customer without undue delay. Where Riera Studio is controller, regulator and individual notification is assessed under applicable UK and EU law.
Customer responsibilities
Customers must use individual accounts, secure devices and suitable passwords; limit roles to what each person needs; remove former staff promptly; review exports before sharing; and notify Riera Studio of suspected compromise.
Customers remain responsible for lawful data entry, their own privacy notices, business continuity and keeping independent copies of records needed for tax, insurance or event delivery.
Reporting security concerns
Report a suspected vulnerability or incident to RieraStudio@srfsystems.uk with the affected URL, steps to reproduce, potential impact and safe supporting evidence. Do not access other customers’ data, disrupt the service or publish an unresolved vulnerability.
Good-faith reports are reviewed and prioritised according to risk. Riera Studio does not currently operate a paid bug-bounty programme.
Legal operator and contact
Riera Studio is operated by Sergi Riera Félix, trading as SRF Systems, a sole trader in the United Kingdom.
Service address: United Kingdom. The full geographic address for formal service is stated on contractual order documents and is available from the contact email.
Email: RieraStudio@srfsystems.uk
