Skip to main content
OneCount
Menu
← Back to home

Security at OneCount

Last updated: 2026-07-12

OneCount Pty Ltd · ACN 695 536 415 · ABN 29 695 536 415

This page describes controls and limits that are present today. It does not replace a customer's own risk assessment and does not claim a certification or uptime commitment.

Current role model

  • Staff use day-to-day count workflows.
  • Manager-level mobile users receive management and insights surfaces in addition to staff workflows.
  • Owner-only website controls cover organisation and member governance.

These public roles are owner, manager, and staff. This summary does not claim per-venue staff assignment, manager invitation rights, backend-enforced manager-only finalisation, or permanent retention for every session.

Authentication and tenant isolation

Supabase provides authentication and the primary Postgres data service. Authenticated user paths use Supabase row-level security to limit organisation data access.

Some privileged server paths can bypass row-level security. Those paths therefore require separate authorization and tenant checks in the server code; row-level security alone is not a complete control for privileged operations. We do not publish a live scanner finding count.

Transport, hosting, and monitoring

Web traffic uses HTTPS. The website and dashboard run through Vercel, while product identity and operating data are handled through configured Supabase services.

Sentry is conditional mobile monitoring when its mobile DSN is configured. The website has no Sentry Next.js runtime today and relies on Vercel and runtime logging. Monitoring does not prove that every dependency is healthy; see Service status for the current manual incident process.

Responsible disclosure

Report a suspected vulnerability privately to hello@onecount.ai. Do not include passwords, secret keys, or customer data in the initial message. No response-time SLA is published.

The standard contact is also published in security.txt.