Data & security
Viridis applies least-privilege access, encrypted transport, server-only credentials, reviewed database changes, and explicit provenance labels. These controls reduce risk; they are not a certification or guarantee.
Data handling
Design partners agree a data schedule before sharing sensitive parcel or ownership documents. Public request forms are for contact and high-level project context only. Sensitive source files are not requested through the public site.
Technical controls
- TLS in transit, container isolation, non-root application runtime, and security response headers.
- Supabase row-level security and server-only service credentials for privileged operations.
- Invite-only authentication and protected operator, parcel, document, monitoring, and settlement routes.
- Structured operational logs that exclude request bodies, credentials, and direct personal identifiers.
- Commit-aware health checks, automated release verification, and a documented image rollback path.
Limitations and partner responsibilities
The beta has not been represented as SOC 2, ISO 27001, FedRAMP, or another certified system. Partners must confirm they have authority to share data, minimize uploads, classify sensitive records, and use an agreed transfer method. Field and legal records remain authoritative.
Responsible disclosure
Send a concise report to justin@viridisconservation.com. Include the affected URL, observed impact, and safe reproduction steps. Do not access another person’s data, disrupt service, or publish sensitive evidence.