Row Level Security, enforced by Postgres

Security built into the database, not bolted onto the UI

AcreTerminal handles sensitive leasing, asset-management, financial and legal data. Hiding a button is not authorisation — every control below is enforced where it can't be bypassed: the database layer itself.

rls_isolation.sql — live run, two real tenantsAll passed
User A can read Org A's properties, leases, assets — but not Org B's
User A's UPDATE against Org B's property affects 0 rows
User A's INSERT into Org B is rejected outright
User B independently confirms the mirror image, including AcreYield's assets and health records

Run directly against production with real fixtures (self-cleaning, zero trace left) — not a unit test against a mock. See docs/rls.md for the full methodology.

Defense in depth

Four layers, and the database is the one that can't be skipped

Your browser

No service-role key, no privileged query ever ships to client code.

Server actions

Every write validates the caller's organisation and permission before touching the database.

Row Level Security
Real boundary

Postgres itself refuses any row outside the caller's organisation — the database is the real boundary, not the UI.

Postgres

Encrypted at rest and in transit, with append-only audit logging on every material change.

AcrePayGuard

How an approval becomes tamper-evident, step by step

Early access runs this exact pipeline against our own private EVM chain; a public network is on the roadmap for general availability.

Canonicalise (RFC 8785)

The approved invoice revision and its verification result turn into one exact, fixed JSON form — the same facts always produce the exact same bytes, so formatting or field order can never quietly change the result.

Hash (keccak256)

That canonical JSON is hashed and combined with an event type and your organisation's own private on-chain identifier into a single domain-separated commitment — never the raw invoice data itself.

Commit to EvidenceRegistry.sol
On-chain

The commitment is submitted to a Solidity smart contract — access-controlled per tenant via OpenZeppelin, append-only, non-upgradeable — and recorded on-chain.

Independently verifiable, anytime

Anyone holding the original record can recompute the same hash and check it against the registry themselves — verification never depends on trusting AcreTerminal's own database.

Security controls

Multi-tenant isolation

Every table enforces Row Level Security by organisation membership — one tenant's properties, leases and documents are never visible to another.

Role-based access

Your team, DesiAcres staff and external-partner roles each carry distinct permissions, down to which billing or legal records they can see.

Secrets stay server-side

The database service-role key never reaches the browser. All privileged operations run through server actions and route handlers.

Audit logging

Every material create/update — organisations, leases, transactions, invoices — writes an append-only audit-log entry with actor, role and before/after state.

Data provenance

Actual records, estimates and assumptions are visually distinguished throughout the product, with source, date and confidence attached to every calculated figure.

Document handling

Uploaded documents are stored in access-controlled buckets with signed URLs; a malware-scanning adapter interface is in place for when a scanning provider is configured.

Tamper-evident evidence (AcrePayGuard)

An approved invoice's evidence is recorded on a tamper-evident ledger — a later edit to the record is detectable, not just logged in a table someone could quietly alter. This confirms the integrity of the recorded evidence, never the accuracy of the original invoice. Early access runs on our own private ledger.

What we deliberately don't do

  • Hide authorisation behind UI buttons only
  • Ship the database service-role key to the browser
  • Let one algorithm change silently affect every organisation
  • Claim regulatory certifications we don't hold

Global data handling

India is our fully operational market, and Indian organisations' data is handled under applicable Indian law. As we expand — currently to 9 additional countries on our roadmap — we apply the same technical controls above (tenant isolation, role-based access, audit logging) universally by default. We do not yet hold formal regulatory certifications or legal registrations outside India, and we won't claim otherwise on this page. If your organisation needs country-specific compliance documentation, a data-processing agreement, or details on where a particular market stands, contact us directly — that's a conversation with our team, not a page of badges.

Reporting a vulnerability

If you believe you've found a security issue, contact us before disclosing it publicly. We take reports seriously and respond promptly.

Contact security

We use only strictly necessary cookies — to keep you signed in and remember which organisation you're working in. We don't run analytics or advertising cookies today. See our Privacy Policy for details.