Per-user data isolation
Supabase Auth plus row-level policies enforce user-scoped reads and writes.
Security and Trust
Cora protects user data through layered technical controls and explicit clinical boundaries, with a roadmap for full enterprise compliance operations.
Supabase Auth plus row-level policies enforce user-scoped reads and writes.
Inbound Twilio traffic is accepted only when request signatures validate.
Verification codes and API tokens are stored as hashes, not plaintext credentials.
Ingested files use private storage and time-limited signed URLs for controlled retrieval.
Service-role actions stay on trusted server routes and worker runtimes only.
Explore the product architecture or create your account and begin onboarding.