Security built in
BizBrew keeps each business's data separate, encrypts every connection and checks access on every request — on every plan, with no extra configuration.
Security is not an add-on
On a platform shared by many businesses, separating their data is the most important job. BizBrew is built around it, and you get the same protection on the free plan as on the Pro plan.
How we protect your data
Tenant isolation
Every record belongs to one business. Our backend filters every query by the business of the signed-in user. Direct database access is closed to users, and PostgreSQL row-level security is enabled on every table as an extra safeguard.
Proven authentication
Sign-up, sign-in, password recovery and sessions run on Supabase GoTrue with short-lived JWTs and automatic token refresh. Passwords are stored only as hashes.
Role-based access
Business owners and staff have separate roles, and staff access can be narrowed with permissions. The backend checks the caller's membership and role before it acts.
Encryption in transit
All traffic uses HTTPS. Custom domains receive TLS certificates automatically, so your customers always see a secure connection.
Audit logging
Significant actions — such as creating a business, verifying an account and administrative changes — are recorded with who did what and when, for review when you need it.
GDPR support
Data is separated per business, you can export your records, we sign a data processing agreement with you, and we publish our sub-processors.
How data isolation works
All businesses share one database, and every table carries a tenant ID. Isolation is enforced in the application on every request; database-level protections are an extra line of defence.
Request arrives
The business is identified from the domain or subdomain the request was sent to.
Authentication and membership
The backend verifies the user's session token, confirms the user belongs to that business and checks the user's role.
Tenant-filtered queries
Every database query the backend runs is filtered by that business's ID. Users cannot query the database directly, and row-level security on every table is an extra safeguard.
Response returned
Only that business's data is returned, over an encrypted HTTPS connection.
Ready to build on a secure foundation?
Start for free. No credit card required.