Security
Last updated: August 11, 2026
Workspace isolation
Every account belongs to a workspace, and every query against your data is scoped by row-level security policies enforced at the database layer. One workspace can never read or write another workspace's contacts, deals, projects, invoices, or team records.
Authentication
Sign-in is handled by Supabase Auth — passwords are never stored in plain text. New account creation is protected by hCaptcha to block automated signup abuse, and sessions are managed with secure, expiring cookies.
Access control
Within a workspace, role-based permissions (owner, admin, member) control what each teammate can see and do, down to per-module and per-feature access — for example, granting a teammate view-only access to Invoices while giving them full access to Deals.
Data in transit and at rest
All traffic between your browser and Celaris is encrypted over HTTPS/TLS. Data at rest is encrypted by our underlying infrastructure provider.
Responsible disclosure
If you believe you've found a security vulnerability in Celaris, please email hello@celaris.cloud with details. We ask that you give us a reasonable window to investigate and address the issue before any public disclosure.
Celaris