Security
A plain summary of how we protect EmiraBooks accounts and company data. We only list measures we actually run today.
Last updated: October 11, 2026
Tenant isolation
Each company is treated as its own workspace. Application checks scope reads and writes to the active company, so one customer cannot open another customer’s records through normal app flows.
Row Level Security (RLS)
Postgres Row Level Security policies run on Supabase for tenant and admin tables. Policies and API guards were hardened so access stays company-scoped even if a request is crafted outside the UI.
Encryption at rest
Database and file storage sit on Supabase. Supabase encrypts data at rest on the managed platform. Transport uses HTTPS/TLS.
Hosting
The web app is hosted on Vercel. Database, authentication and file storage run on Supabase. Our privacy policy records the Supabase storage region as Indien (Mumbai, AWS ap-south-1). Details and subprocessors are listed under Privacy.
Two-factor authentication (2FA)
Account holders can enable 2FA in settings. Admin access also supports 2FA. We recommend turning it on for every production login.
Monitoring
We use Sentry for application error reporting. Events are scrubbed for common PII (emails, IBANs, UAE TRNs) before send, and default PII capture is disabled.
What we do not claim
EmiraBooks is software support for bookkeeping and compliance. It is not tax advice and is not an FTA accreditation or approval. Final filings remain with you or your advisor.
