Fumana Pilot Security Overview
Access Model
Fumana uses tenant-based organisation access so users work inside authorised organisation workspaces.
Supabase Auth provides authentication, and Fumana applies role-based controls for owners, admins, editors, viewers, and platform admins.
Platform And Organisation Separation
Platform admin is separate from organisation membership. Platform admins can provision organisations and view high-level platform readiness, but they do not automatically browse client sermon, transcript, media, search, or Clip List content.
Organisation admins manage their own organisation's Drive connection, members, invites, sync review, and processing controls.
Drive And Processing
Google Drive access is intended to be authorised by the client organisation and used for selected media metadata and processing workflows.
Heavy media processing runs through queue/worker infrastructure, keeping long-running processing separate from the production web runtime where configured.
Secrets And Logs
Server secrets such as Supabase service-role keys, Google client secrets, Google tokens, and OpenAI keys should be stored only in server or worker environments and must not be exposed to the browser.
Processing logs and audit events should avoid secrets, OAuth tokens, full transcript bodies, and unnecessary sensitive content.
Pilot Limitations
The pilot service has not yet been independently penetration tested and does not yet include a final lawyer-reviewed compliance pack.
Security controls, audit coverage, operational documentation, and legal review will improve over time as the product matures.
Reporting
Security issues should be reported to the designated Fumana/Looped Tech pilot contact. A formal security contact and escalation process should be finalised before broad commercial rollout.