Draft, requires legal review before production use
This document was written from what the running system actually does: the edge gate, the database and its row level security, and the third party requests these pages make. It has not been reviewed by a lawyer. Anything that is a business decision rather than a fact about the software is marked in place rather than guessed at.
Security
Security
What actually protects your data here, said precisely, including the parts that are not finished. A security page that only lists strengths is not much use to anyone.
How to report something
Email hello@drivenmemory.com with enough detail to reproduce it. Please do not open a public issue for a vulnerability, and please do not test against other people's accounts or data.
Needs a decision: a response time commitment, and whether a bounty is offered. Neither is promised here, because neither has been decided.
In scope
drivenmemory.com and the application served from it.
Out of scope
Products published by companies on the marketplace are those companies' own software; report those to them. Findings against our processors belong to Supabase and Cloudflare respectively.
Where the boundary actually is
PostgreSQL row level security is the security boundary. Every table carries policies, and they are evaluated by the database against the signed in identity on every query. A control hidden in the interface is a usability decision and never an access control, which is why the interface says so on the screens where a control is disabled.
Company access is ranked: an Owner outranks an Admin, which outranks an Editor. Company settings require Admin or above. Company membership changes require the Owner. Listing changes require Editor or above.
The session, and the gate in front of the site
Signing in mints the driven_session cookie over the network, on our own endpoint, after the token is validated. The cookie is HttpOnly (script cannot read it) and SameSite=Lax, and the edge gate reads it before any protected page is served. The gate fails closed: if the authentication service cannot be reached, protected pages are refused rather than served. Signing out clears the cookie.
One residual fact stated plainly: the browser talks to the database directly as you, so your access token also lives in browser storage, as it does in any application built on this authentication model. Script injection on this site could reach it, which is one reason the content security policy below is strict and every user-controlled value is rendered as text.
Headers the site ships
Every response carries a content security policy that permits scripts from this origin and the sign-in CAPTCHA only, no third-party analytics origin, no framing by other sites, MIME sniffing off, a strict referrer policy, and a permissions policy that declines camera, microphone, location, payment and USB. Since 26 August 2026 typefaces are self-hosted, so the policy no longer permits any font or style origin belonging to a third party beyond the CAPTCHA's own.
What has been tested
Authorization is exercised against the running database rather than reasoned about, by automated suites that run against both a local build and the deployed site. Anonymously: every private table returns nothing and every write is refused. Authenticated, using two real accounts: an account sees nothing of another account's saved listings, private notes, enquiries, drafts, memberships or profile rows, and cannot write to any of them, including with forged identifiers; cross-company reads and writes are refused; uploading into another company's storage path is refused. The gate is tested closed for anonymous visitors, open for a valid session, and closed again after sign-out, including that a forged or shape-valid token does not open it. Write attempts in these tests run inside transactions that are rolled back, or against temporary rows that are removed and then verified gone.
What the design already does
The site sends no analytics and loads no tracker, so there is no third party recording what you look at. Since 26 August 2026 even typefaces are served from this origin. Community profiles are hidden until their owner turns them on. Saved listings and private notes are readable by their owner alone, and a publisher is never told who saved a listing. Passwords are handled by the authentication service and never pass through this application's own code. Sign-in is protected by a CAPTCHA.
Safe harbour
Needs a decision: whether a formal safe harbour is offered to good faith researchers. This is a legal commitment and is not made here by default.