Authentication
Individual email-and-password accounts use Supabase authentication. Password recovery uses expiring, single-use verification challenges.
This center explains what CONHUBAI does today, what remains device-local or request-only, and which organization controls are still planned. Pilot security reviews use the same distinction.
These statements describe current application behavior. Provider and contract evidence can be reviewed during a scoped pilot.
Individual email-and-password accounts use Supabase authentication. Password recovery uses expiring, single-use verification challenges.
Protected product routes can require a signed, expiring HTTP-only preview cookie. The public RFI example does not unlock product access.
Administrative authorization is tied to immutable user identifiers rather than email-address matching.
HTTPS, HSTS, content-security policy, request-origin validation, restricted framing, MIME protection, and bounded request bodies are configured.
Signed-in Adviser conversations and controlled project context can be stored with the account in Supabase. Billing and product-event records are server controlled.
Preconstruction and certain preview workspace drafts remain on the current device. They are labeled as device data and can be exported or cleared by the user.
Uploaded working files are processed for the active request and are not presented as a permanent account document library. File type, size, and unsafe Office archive content are checked.
CONHUBAI uses external AI API providers to process submitted prompts and authorized files. CONHUBAI does not use customer project content to train its own models. Provider processing terms are reviewed during a pilot.
Paid access is granted only after signed provider events. Checkout, renewal choice, cancellation, receipts, refunds, disputes, and webhook idempotency are implemented.
Users can download generated records and export supported workspace data. Device drafts can be cleared locally; account-data deletion requests are handled through Support.
Signed-in conversations and controlled project context may be saved to the account.
Account access · server storedPreconstruction and selected preview workspace drafts stay in the browser until export or clear.
Current device · user controlledSelected files are used for the active request and are not presented as a permanent document repository.
Transient processing · provider involvementProcore, Autodesk, SharePoint, P6, approved document control, and company systems remain authoritative.
External system · not replacedThese items are disclosed for planning. They must not be treated as available controls in a proposal or security questionnaire.
Not currently offered as an organization control. SAML SSO and enforced MFA remain planned and require security validation.
Individual accounts exist today. Separate-user organization roles, project permissions, invitations, and managed seats are not represented as complete.
Billing and selected product events are recorded, but a customer-facing organization audit-log center is not yet available.
CONHUBAI does not currently claim SOC 2, ISO 27001, or another independent security certification. Certification planning follows pilot requirements.
Dedicated tenant, private-cloud, and customer-managed model deployment are not currently advertised as available.
Share authentication, retention, residency, subcontractor, incident-response, export, and certification requirements before a pilot is scoped.