Reference
Security model
How Retensis protects tenants, storage, integrations, OAuth, AI boundaries, and billing operations.
LiveAll plans
Primary controls
- Supabase Auth and RLS for user and workspace data.
- Explicit effective-plan resolution for Pro and Team access.
- Presigned R2 uploads and playback with owner checks.
- Service-role-only Edge Functions with fail-closed internal authentication.
- Private-network and redirect protection for fetched URLs and outbound integrations.
- Signature verification and idempotent processing for Stripe and RevenueCat webhooks.
- OAuth PKCE, opaque token hashes, short authorization-code lifetime, and refresh-family reuse detection.
- Prompt boundaries that treat comments, pages, and competitor content as untrusted data.
- MCP input validation and per-tool output allowlists.
Security reporting
Do not include credentials, private videos, tokens, or personal data in a report. Use the Contact page for initial coordination and provide the minimum information needed to reproduce the issue safely.