This page is written for whoever on your team has to sign off before GiggEx touches real hospital data — with a clear line between what's already true and what's still in progress.
Every table in the database starts with row-level security enabled and zero access policies. Access is added deliberately, per reviewed need, scoped to authenticated users — never open by accident.
What a user can see and do is tied to their role and facility — an admin at one hospital doesn't get a side door into another's data.
GiggEx runs on Supabase (Postgres) for data and Netlify for hosting — established, widely-audited infrastructure providers, not a homegrown stack.
API keys and access tokens live only where they're supposed to — never in application code, chat logs, or anywhere they could leak into a document.