Security
Last updated September 25, 2026
Decize stores an organization’s decision record. We protect it with workspace isolation, explicit membership, and narrowly scoped integrations.
Encrypted transport
Traffic between clients and Decize uses HTTPS/TLS. Supabase provides encryption for stored database data.
Organization isolation
Decision records require an organization identity. Row-level security separates workspaces on reads, and server-side code scopes each write to its workspace.
Role-based access
Authenticated membership and organization roles control access to management, settings, analytics, and exports.
Audited operations
Sensitive organization changes create audit events, and signed action links are verified before writes.
Controlled capture
Inbound email capture resolves senders to organization members and applies allowlists and rate limits.
AI and integrations
AI features send only the context needed for the requested organization analysis to configured model providers. The email integration processes messages only when they are sent or forwarded to a workspace capture address. See our Privacy Policy for the current provider list.
Organization controls
- Owners and managers can manage the roster and organization settings.
- On the Team plan and above, organization decisions can be exported in a portable format.
- Decision records can be updated or deleted by authorized members.
Reporting a vulnerability
Send security reports to support@decize.app, including reproduction steps where possible. Please allow a reasonable period for investigation before public disclosure. Decize does not currently operate a paid bug-bounty program.
Limits
No online service can guarantee perfect security. Decize is under active development; we continue to review access controls, dependencies, and operational safeguards as the service evolves.
For the definitions and sample rules behind decision-health reporting, see the decision quality methodology.