Security

A plain summary of how we protect EmiraBooks accounts and company data. We only list measures we actually run today.

Last updated: October 11, 2026

Tenant isolation

Each company is treated as its own workspace. Application checks scope reads and writes to the active company, so one customer cannot open another customer’s records through normal app flows.

Row Level Security (RLS)

Postgres Row Level Security policies run on Supabase for tenant and admin tables. Policies and API guards were hardened so access stays company-scoped even if a request is crafted outside the UI.

Encryption at rest

Database and file storage sit on Supabase. Supabase encrypts data at rest on the managed platform. Transport uses HTTPS/TLS.

Hosting

The web app is hosted on Vercel. Database, authentication and file storage run on Supabase. Our privacy policy records the Supabase storage region as Indien (Mumbai, AWS ap-south-1). Details and subprocessors are listed under Privacy.

Two-factor authentication (2FA)

Account holders can enable 2FA in settings. Admin access also supports 2FA. We recommend turning it on for every production login.

Monitoring

We use Sentry for application error reporting. Events are scrubbed for common PII (emails, IBANs, UAE TRNs) before send, and default PII capture is disabled.

What we do not claim

EmiraBooks is software support for bookkeeping and compliance. It is not tax advice and is not an FTA accreditation or approval. Final filings remain with you or your advisor.

Related