Member protection

Security & Privacy

The portal protects identity, financial administration and official work with verified access, role boundaries and an accountable record of important decisions. Last updated 18 August 2026.

Verified member access

A claimed Deck Name is tied to one Supabase Auth UID. Email verification activates protected portal access automatically. If Deck access is later closed for security, protected data and Anchor Points fail closed.

Passwords and sessions

Passwords are handled by Supabase Auth and are not visible to Frigate officials or stored in portal tables. Password reset links and login sessions use Supabase's protected authentication flow.

Role and record isolation

Postgres row-level security and server-side role checks restrict member, Purse, FC, FCC, Scribe, Crier and administrator records. Server-only credentials are never sent to the browser.

Financial evidence

Payment and financial evidence buckets are private. Authorised users receive short-lived signed access instead of public file links, while approvals and corrections remain auditable.

Coral Alerts

Notifications are optional and start only after you select Enable alerts and approve the browser prompt. Lock-screen messages are privacy-safe; contribution amounts, account details and private approval notes stay inside the signed-in portal.

Correction and incident reporting

If your identity or portal record is wrong, or you suspect unauthorised access, stop using the affected session and report it to the FC through the established chapter channel. Include your Deck Name, the time and what you observed, but never send your password.