Application boundary
Next.js server-side routes keep Supabase service-role credentials out of the browser.
Trust & Compliance / Information security
Technical and application safeguards support the WDL website, enquiry handling and administrative access.
Next.js server-side routes keep Supabase service-role credentials out of the browser.
Supabase PostgreSQL Row Level Security is enabled; public clients do not receive an anonymous insert policy.
The enquiry list requires a password-verified, HMAC-signed session stored in an HttpOnly cookie.
Production cookies are configured Secure and SameSite Strict, with an eight-hour maximum age.
Contact and RFQ requests use server-side validation, length limits, sanitization, honeypots and timing checks.
Origin/Host checks and basic per-IP application throttling reduce common automated abuse.
The deployment design places Nginx and HTTPS in front of Next.js, which listens only on 127.0.0.1:3088.
Vendor onboarding
Prospective clients, procurement teams and research partners may request supporting information for due diligence. Documentation is provided by request and subject to availability, confidentiality and appropriate review.