Security

How Infrenta protects project access and data.

Infrenta uses organization-scoped access, role-based permissions, managed authentication, HTTPS, and selected revision history so project information stays with the customer organization that owns it.

This page describes controls that exist in the product and in the published Terms and Privacy Policy. Those documents remain authoritative.

Security at a glance

  • Organization-scoped data

    Customer records are associated with companies. Supported data paths use membership checks and row-level policies to keep organizations separate.

  • Roles and permissions

    Authorized Users receive role- and permission-based access inside their organization. Administrators grant, change, or revoke that access.

  • Managed authentication

    Sign-in and sessions use Supabase Auth. The public marketing site is separate from the authenticated application.

  • Encrypted connections

    Browser and application traffic uses HTTPS/TLS.

  • Controlled project history

    Selected workflows — including estimates, drawings, and documents — keep revisions and change history for review.

  • Customer-owned data

    As between the customer and Infrenta, the customer retains ownership of Customer Data. The Terms do not transfer that ownership.

How a request reaches project data

Normal product use stays inside the authenticated application and managed data stores. AI-assisted features are a separate, requested path.

Application path

  1. 01

    User browser

    Authorized User on the authenticated application.

  2. 02

    HTTPS / TLS

    Encrypted connection to the application host.

  3. 03

    Infrenta application

    Product UI and application services.

  4. 04

    Authentication and authorization

    Supabase Auth session, organization membership, roles, and permissions.

  5. 05

    Supabase database and storage

    Company-scoped records and files on supported paths.

Optional AI-assisted path

  1. 01

    User invokes an AI-assisted feature

    Only when that feature is requested.

  2. 02

    Requested content

    Prompts, attachments, or other Customer Data needed for that operation.

  3. 03

    Third-party AI provider

    Assisted features may send requested content to third-party AI providers when a user invokes them. Providers can change.

Tenant isolation and authorization

Infrenta is multi-tenant. A project record belongs to a company. Authorized Users see the Customer Data their organization and permissions allow — not every tenant on the platform.

  • Organization membership and company-scoped records are the primary isolation boundary.
  • Supported database paths enforce that boundary with row-level security and helpers such as current company and project access checks.
  • Application routes also check roles and permissions before a workspace is shown.
  • Some privileged actions can be written to an authorization audit log. That log is not a SIEM or a complete monitoring product.

Not every historical table or file path used identical controls. Public statements here describe supported product paths, not a guarantee of absolute isolation on every historical path.

Creating a project

Authentication and access

The authenticated application uses managed Supabase Auth. Users sign in with organization credentials. Sessions are established and refreshed by that provider. The marketing website does not share that login.

  • Organizational administrators provision Authorized Users and assign roles using the permissions available in the Services.
  • Password and session handling follow the managed authentication provider.
  • Customer must protect credentials and notify Infrenta if it becomes aware of unauthorized access.

Trust the record, not just the login.

Access control decides who can open a project. Traceability decides whether the number on the screen is the issued one.

  • Estimate revisions

    Estimates keep revision history so reviewers can see which issued calculation is authoritative.

    Estimate revisions

  • Drawings and documents

    Drawing versions and selected document history stay attached to the project instead of living only in email.

    Drawings and documents

  • Downstream identity

    Quantities and assumptions can carry from GeoLab and estimating into procurement, controls, and execution on the same project record.

    Downstream identity

Not every record type is immutable. Selected workflows preserve revisions; others remain ordinary editable records.

Infrastructure and encryption

Infrenta relies on managed cloud providers for portions of its database, authentication, storage, and infrastructure security.

  • Application data, authentication, and file storage use Supabase.
  • Browser connections use HTTPS/TLS.
  • Storage and database protections rely on those providers’ controls. This page does not describe a proprietary Infrenta encryption appliance.

AI-assisted features and Customer Data

Some features use machine learning or large language models. Those features may send prompts, files, or other Customer Data to service providers so the requested result can be returned.

  • Processing occurs when a user invokes a feature that requires it — not as a background export of the whole project.
  • Assisted features may send requested content to third-party AI providers when a user invokes them. Providers can change.
  • Infrenta will not use Customer Data to train general-purpose or public foundation AI models.
  • That statement does not mean Customer Data stays only on Infrenta systems. Infrenta does not promise those providers’ retention practices beyond applicable privacy obligations and its agreements with them.
  • Engineering and commercial Outputs still require professional review. Deterministic calculations are not presented as AI-generated totals.

Privacy PolicyTerms of Service

Data ownership and privacy

As between Customer and Infrenta, Customer retains ownership of Customer Data. Infrenta receives a limited license to host, process, and display that data to provide the Services.

  • The Privacy Policy explains what personal information the marketing site and product may process.
  • Deletion or export requests are handled under the customer agreement, organization instructions, and applicable law. There is no promised self-service account-purge workflow.
  • Terms and Privacy remain authoritative if this summary and those documents differ.

Security is shared

Infrenta designs organization, role, and infrastructure controls. Customers operate their organizations.

  • Protect credentials and do not share them with anyone who is not an Authorized User.
  • Manage membership and assign permissions that match each person’s job.
  • Tell Infrenta about suspected unauthorized access.

Enterprise security review

Security questionnaires, architecture discussions, and additional contractual requirements can be reviewed during a commercial evaluation. This page does not promise that every requested control can be met.

Contact Security

Report a vulnerability

If you believe you found a security issue in Infrenta, email security@infrenta.com. Useful reports include the affected URL or workspace, steps to reproduce, and the impact you observed.

security@infrenta.com

Please report issues privately so they can be reviewed before public discussion.

Security questions

  • Records are company-scoped. Supported paths use organization membership and row-level policies. Authorized Users see what their organization and permissions allow. That is a description of implemented controls, not a guarantee of absolute isolation on every path.

Review the controls, then talk through the ones your team still needs.

Privacy and Terms stay authoritative. Security questionnaires belong in a commercial evaluation.