Security

Last updated September 25, 2026

Decize stores an organization’s decision record. We protect it with workspace isolation, explicit membership, and narrowly scoped integrations.

  1. Encrypted transport

    Traffic between clients and Decize uses HTTPS/TLS. Supabase provides encryption for stored database data.

  2. Organization isolation

    Decision records require an organization identity. Row-level security separates workspaces on reads, and server-side code scopes each write to its workspace.

  3. Role-based access

    Authenticated membership and organization roles control access to management, settings, analytics, and exports.

  4. Audited operations

    Sensitive organization changes create audit events, and signed action links are verified before writes.

  5. Controlled capture

    Inbound email capture resolves senders to organization members and applies allowlists and rate limits.

AI and integrations

AI features send only the context needed for the requested organization analysis to configured model providers. The email integration processes messages only when they are sent or forwarded to a workspace capture address. See our Privacy Policy for the current provider list.

Organization controls

  • Owners and managers can manage the roster and organization settings.
  • On the Team plan and above, organization decisions can be exported in a portable format.
  • Decision records can be updated or deleted by authorized members.

Reporting a vulnerability

Send security reports to support@decize.app, including reproduction steps where possible. Please allow a reasonable period for investigation before public disclosure. Decize does not currently operate a paid bug-bounty program.

Limits

No online service can guarantee perfect security. Decize is under active development; we continue to review access controls, dependencies, and operational safeguards as the service evolves.

For the definitions and sample rules behind decision-health reporting, see the decision quality methodology.