Reference

Security model

How Retensis protects tenants, storage, integrations, OAuth, AI boundaries, and billing operations.

LiveAll plans

Primary controls

  • Supabase Auth and RLS for user and workspace data.
  • Explicit effective-plan resolution for Pro and Team access.
  • Presigned R2 uploads and playback with owner checks.
  • Service-role-only Edge Functions with fail-closed internal authentication.
  • Private-network and redirect protection for fetched URLs and outbound integrations.
  • Signature verification and idempotent processing for Stripe and RevenueCat webhooks.
  • OAuth PKCE, opaque token hashes, short authorization-code lifetime, and refresh-family reuse detection.
  • Prompt boundaries that treat comments, pages, and competitor content as untrusted data.
  • MCP input validation and per-tool output allowlists.

Security reporting

Do not include credentials, private videos, tokens, or personal data in a report. Use the Contact page for initial coordination and provide the minimum information needed to reproduce the issue safely.