Security architecture

Designed so sensitive family data is protected before upload.

Privara uses a zero-knowledge mindset with client-side encryption, strict Supabase RLS, audit logging, MFA, and secure billing boundaries.

Privara
Client-side AES-GCM for vault secrets when your key is configured
Implemented as a first-class architecture concern with clear client, server, database, and audit boundaries.
Privara
Supabase RLS scoped to auth.uid() on exposed tables
Implemented as a first-class architecture concern with clear client, server, database, and audit boundaries.
Privara
MFA, device stance, and step-up protections on our roadmap
Implemented as a first-class architecture concern with clear client, server, database, and audit boundaries.
Privara
Private timeline — vault edits plus auth session events when you engage
Implemented as a first-class architecture concern with clear client, server, database, and audit boundaries.

Ready to protect your family?

Start with the essentials — your workspace stays private behind Supabase Auth and row isolation.

Create your vault