Trust & security

Security enforced at the database row

Your product model is the most valuable engineering asset your company owns. We protect it the way engineers would want it protected: access control in the database itself, a complete audit trail, and an export path that means the data is always yours. No badge wall — just how it’s built.

Architecture

Every table behind a policy

Manufacts runs on Postgres with row-level security on every table. Who can see or change a row is decided by database policies, not by hoping every code path checks permissions correctly. A dealer’s query physically cannot return another manufacturer’s rows.

On top of that sits role-based access with four roles, each scoped to what that job actually needs:

policy · configurations enforced in the database

create policy dealer_reads_own
  on configurations for select
  using (
    org_id = auth.current_org()
    and role_in('dealer', 'admin')
  );

Not middleware. Not an if-statement. The database itself refuses the row.

Admin

Full control of the account: users, roles, plants, and platform settings.

Engineer

Authors the product model — parts, rules, BOM logic — through governed change workflows.

Dealer

Configures and quotes from the published catalog. Sees their orders, never your cost model or another dealer’s book.

Viewer

Read-only access for finance, operations, or auditors who need to see, not touch.

Audit trail

Every order, explainable for life

In manufacturing, “why did the system do that?” is a question you may be asked years after the order shipped. The platform is built to always have an answer.

Attributed

Every change records who made it — a person, a role, a timestamp. Never an anonymous edit.

Timestamped

The full history of every part, rule, price, and BOM is kept in order, forever.

Reversible

Changes can be walked back. History is an undo path, not just a log file.

Frozen at order time

Rule sets are versioned and frozen when an order is placed — so every order stays explainable for life, even as the catalog evolves.

Because rule sets are frozen and versioned per order, you can re-open a two-year-old order and see exactly which rules resolved its BOM — even if the catalog has changed a hundred times since.

Data ownership

Your catalog is yours. Full stop.

The parts, BOMs, rules, price books, and drawings in Manufacts are your engineering IP — we’re the custodian, not the owner. You can export the whole model at any time: catalog and BOM data to CSV, drawings to DXF. No export tier, no exit fee, no request queue.

We think a platform should earn renewal with the product, not with the difficulty of leaving it.

  • CSV export of parts, BOMs, and price books — any time, self-serve
  • DXF export of drawings for use in any CAD system
  • No lock-in by format: everything exports to open, documented formats
  • Your data is never sold, shared, or used to train models for anyone else

Infrastructure

Boring where it should be boring

We build the interesting parts — the resolution engine, the rule model — on deliberately unexciting, well-operated infrastructure.

Supabase-managed Postgres

Your data lives in a managed Postgres instance — a boring, proven database, professionally operated, not a bespoke datastore.

Encrypted at rest and in transit

Data is encrypted on disk and every connection runs over TLS. There is no unencrypted path to your catalog.

Vercel edge hosting

The application is served from Vercel’s edge network, isolated from the database layer and deployed through reviewed, versioned builds.

Row-level security everywhere

Access control is enforced in the database itself — not just in application code — so a bug in a UI can’t become a data leak.

Compliance

Where we are, honestly

We won’t decorate this page with badges we haven’t earned. Here is the current state, plainly:

  • SOC 2 Type II is on our roadmap. The controls it measures — access reviews, change management, audit logging — are how the platform already works day to day; the formal audit is in progress, not complete.
  • GDPR-aligned data handling. We collect the minimum personal data needed to run accounts, honor deletion requests, and don’t sell or share personal data. See our privacy policy.

Responsible disclosure

Found something? Tell us.

If you believe you’ve found a security vulnerability in Manufacts, we want to hear from you before anyone else does. Email us directly and a human who can fix it will read it.

security@manufacts.ai

We commit to acknowledging reports promptly, keeping you informed while we investigate, and not pursuing good-faith researchers who respect our users’ data.

Bring your security questions to the demo.

We'll walk your team through the RLS policies, the audit trail, and the export path on live data — the same 30 minutes where you see your product configured and resolved.

No rip-and-replace — Manufacts runs alongside your ERP and CAD. Prefer email? hello@manufacts.ai