Security
Controls that protect Otter workspaces and candidates.
Tenant isolation
JWT tenant claims + Postgres RLS on every table.
Auth
Supabase Auth (email/password, magic link); MFA planned.
Audit log
Privileged actions and support impersonation are recorded.
Object storage
Resumes in R2 with private buckets; signed URLs for download.
Admin console
Super Admin gated by platform_admins; separate from tenant roles.
Privacy
Tenant-isolated data, private resume storage, audited access, in-app candidate export & anonymize (owners/admins).