MV Workshop is designed around separate workshop tenants, role-based access, Supabase authentication, Row Level Security, secure transport, audit logging and controlled storage. Privileged MV Super Admin accounts are separate from workshop-scoped profiles. Customer branding, inspection records, job cards, parts/labour, invoices and documents are intended to remain scoped to the relevant workshop organisation.
The production service should use administrator MFA for privileged roles, server-side secret storage for SMTP/service credentials, validated upload types, tested backup/recovery, dependency/security updates, incident response, subprocessor due diligence and periodic access reviews. No online service is risk-free and Customer administrators remain responsible for their devices, account management and local security.
This is a public summary rather than the full internal information-security policy.