Secure sessions
HTTP-only secure cookies, Supabase identity validation and explicit session revocation endpoints protect dashboard access.
SIMCOAI protects authentication, provider credentials, API keys and subscription entitlements in the backend.
HTTP-only secure cookies, Supabase identity validation and explicit session revocation endpoints protect dashboard access.
Customer API keys are hashed with server-side pepper support, scoped and shown only when created.
Phone, Setup AI, automation, analytics and API capabilities are checked by backend middleware.
Supabase service access remains server-side while schema migrations enable row-level security.
Stripe raw-body signature validation and optional Twilio signature validation protect provider callbacks.
Potential security issues can be submitted through the security category for priority handling.
Contact security →