Security
How Infrenta protects project access and data.
Infrenta uses organization-scoped access, role-based permissions, managed authentication, HTTPS, and selected revision history so project information stays with the customer organization that owns it.
This page describes controls that exist in the product and in the published Terms and Privacy Policy. Those documents remain authoritative.
Security at a glance
Organization-scoped data
Customer records are associated with companies. Supported data paths use membership checks and row-level policies to keep organizations separate.
Roles and permissions
Authorized Users receive role- and permission-based access inside their organization. Administrators grant, change, or revoke that access.
Managed authentication
Sign-in and sessions use Supabase Auth. The public marketing site is separate from the authenticated application.
Encrypted connections
Browser and application traffic uses HTTPS/TLS.
Controlled project history
Selected workflows — including estimates, drawings, and documents — keep revisions and change history for review.
Customer-owned data
As between the customer and Infrenta, the customer retains ownership of Customer Data. The Terms do not transfer that ownership.
How a request reaches project data
Normal product use stays inside the authenticated application and managed data stores. AI-assisted features are a separate, requested path.
Application path
01
User browser
Authorized User on the authenticated application.
02
HTTPS / TLS
Encrypted connection to the application host.
03
Infrenta application
Product UI and application services.
04
Authentication and authorization
Supabase Auth session, organization membership, roles, and permissions.
05
Supabase database and storage
Company-scoped records and files on supported paths.
Optional AI-assisted path
01
User invokes an AI-assisted feature
Only when that feature is requested.
02
Requested content
Prompts, attachments, or other Customer Data needed for that operation.
03
Third-party AI provider
Assisted features may send requested content to third-party AI providers when a user invokes them. Providers can change.
Tenant isolation and authorization
Infrenta is multi-tenant. A project record belongs to a company. Authorized Users see the Customer Data their organization and permissions allow — not every tenant on the platform.
- Organization membership and company-scoped records are the primary isolation boundary.
- Supported database paths enforce that boundary with row-level security and helpers such as current company and project access checks.
- Application routes also check roles and permissions before a workspace is shown.
- Some privileged actions can be written to an authorization audit log. That log is not a SIEM or a complete monitoring product.
Not every historical table or file path used identical controls. Public statements here describe supported product paths, not a guarantee of absolute isolation on every historical path.
Authentication and access
The authenticated application uses managed Supabase Auth. Users sign in with organization credentials. Sessions are established and refreshed by that provider. The marketing website does not share that login.
- Organizational administrators provision Authorized Users and assign roles using the permissions available in the Services.
- Password and session handling follow the managed authentication provider.
- Customer must protect credentials and notify Infrenta if it becomes aware of unauthorized access.
Trust the record, not just the login.
Access control decides who can open a project. Traceability decides whether the number on the screen is the issued one.
Estimate revisions
Estimates keep revision history so reviewers can see which issued calculation is authoritative.
Drawings and documents
Drawing versions and selected document history stay attached to the project instead of living only in email.
Downstream identity
Quantities and assumptions can carry from GeoLab and estimating into procurement, controls, and execution on the same project record.
Not every record type is immutable. Selected workflows preserve revisions; others remain ordinary editable records.
Infrastructure and encryption
Infrenta relies on managed cloud providers for portions of its database, authentication, storage, and infrastructure security.
- Application data, authentication, and file storage use Supabase.
- Browser connections use HTTPS/TLS.
- Storage and database protections rely on those providers’ controls. This page does not describe a proprietary Infrenta encryption appliance.
AI-assisted features and Customer Data
Some features use machine learning or large language models. Those features may send prompts, files, or other Customer Data to service providers so the requested result can be returned.
- Processing occurs when a user invokes a feature that requires it — not as a background export of the whole project.
- Assisted features may send requested content to third-party AI providers when a user invokes them. Providers can change.
- Infrenta will not use Customer Data to train general-purpose or public foundation AI models.
- That statement does not mean Customer Data stays only on Infrenta systems. Infrenta does not promise those providers’ retention practices beyond applicable privacy obligations and its agreements with them.
- Engineering and commercial Outputs still require professional review. Deterministic calculations are not presented as AI-generated totals.
Data ownership and privacy
As between Customer and Infrenta, Customer retains ownership of Customer Data. Infrenta receives a limited license to host, process, and display that data to provide the Services.
- The Privacy Policy explains what personal information the marketing site and product may process.
- Deletion or export requests are handled under the customer agreement, organization instructions, and applicable law. There is no promised self-service account-purge workflow.
- Terms and Privacy remain authoritative if this summary and those documents differ.
Security is shared
Infrenta designs organization, role, and infrastructure controls. Customers operate their organizations.
- Protect credentials and do not share them with anyone who is not an Authorized User.
- Manage membership and assign permissions that match each person’s job.
- Tell Infrenta about suspected unauthorized access.
Enterprise security review
Security questionnaires, architecture discussions, and additional contractual requirements can be reviewed during a commercial evaluation. This page does not promise that every requested control can be met.
Report a vulnerability
If you believe you found a security issue in Infrenta, email security@infrenta.com. Useful reports include the affected URL or workspace, steps to reproduce, and the impact you observed.
Please report issues privately so they can be reviewed before public discussion.
Trust resources
- SecurityThis page — access, tenancy, AI, and review.
- Privacy PolicyHow personal information and Customer Data are described legally.
- Terms of ServiceAccounts, ownership, acceptable use, and commercial terms.
- DocumentationHow projects, estimates, and revisions work in the product.
- IntegrationsLimited, provisioned integrations — not a public API catalog.
- Contact SecurityQuestionnaires, review requests, and vulnerability reports.
Security questions
Records are company-scoped. Supported paths use organization membership and row-level policies. Authorized Users see what their organization and permissions allow. That is a description of implemented controls, not a guarantee of absolute isolation on every path.
Review the controls, then talk through the ones your team still needs.
Privacy and Terms stay authoritative. Security questionnaires belong in a commercial evaluation.