Security
How VenTuhi protects records and controls access.
Access follows the venue and the work
Database access rules and server-side permission checks use venue, role and module permissions to control access to operational records. Management and staff account permissions are assigned by authorised administrators. Paired shared devices and security shift access have separate checks, including the venue and the person’s current access or assignment.
Venues should give people the access they need and remove it when their work or assignment ends.
Records and accountability
Checks and reports retain information about who submitted them. Selected access changes, record changes and report exports are logged for accountability. This supports review without claiming that every action or record view is logged.
Connection and account protection
The hosted website uses HTTPS. Application requests use the configured Supabase HTTPS endpoints, and authentication sessions are checked before being stored. Password recovery uses browser-held verification, and rejected sign-in attempts show a neutral message rather than internal service diagnostics.
Cloudflare Pages delivers the website; Supabase provides authentication, database, file storage and server-side functions. See Service providers.
Before real venue data
Demos use fictional operational records. Before real personal or operational venue data is accepted, backup and recovery arrangements for database records and uploaded files must be implemented, tested and documented, alongside the completed customer agreement and DPA. A written plan alone is not enough.
What we don’t claim yet
We do not claim ISO 27001, SOC 2 or Cyber Essentials certification, a fixed uptime, recovery time or recovery point, or a published backup-retention guarantee. VenTuhi supports venue operations; using it does not certify legal compliance.
Questions and reporting
Contact hello@ventuhi.com about account concerns without sending passwords or live tokens. Suspected vulnerabilities can be reported through our Vulnerability reporting policy.