Trust & Compliance / Information security

Controls designed around the information workflow.

Technical and application safeguards support the WDL website, enquiry handling and administrative access.

Resource
Operational overview
Last updated
25 August 2026
01

Application boundary

Next.js server-side routes keep Supabase service-role credentials out of the browser.

02

Database access

Supabase PostgreSQL Row Level Security is enabled; public clients do not receive an anonymous insert policy.

03

Administrator access

The enquiry list requires a password-verified, HMAC-signed session stored in an HttpOnly cookie.

04

Session attributes

Production cookies are configured Secure and SameSite Strict, with an eight-hour maximum age.

05

Input handling

Contact and RFQ requests use server-side validation, length limits, sanitization, honeypots and timing checks.

06

Request controls

Origin/Host checks and basic per-IP application throttling reduce common automated abuse.

07

Production transport

The deployment design places Nginx and HTTPS in front of Next.js, which listens only on 127.0.0.1:3088.

Vendor onboarding

Need additional vendor documentation?

Prospective clients, procurement teams and research partners may request supporting information for due diligence. Documentation is provided by request and subject to availability, confidentiality and appropriate review.

Request documentation