Security
Careful with other people’s wine.
Horreum holds records that venues make promises on. This page says plainly how those records are kept.
Where data lives
Horreum runs on Supabase, a managed Postgres platform hosted on Amazon Web Services. Data is encrypted in transit with TLS and encrypted at rest by the hosting provider. Automated daily backups are kept by the hosting provider.
Tenant isolation
Every row in the database belongs to a venue, and Postgres row-level security decides who can read or write it. A member sees their own locker; staff see the locations they are assigned to; a venue never sees another venue. These rules are enforced by the database on every query — not by the app, and not by a screen that could be bypassed.
Permissions, enforced in the database
Actions that change records — adding a bottle, logging a pull, approving one, minting labels, reclaiming tags, editing the catalog — run as guarded database functions that check the caller’s role and permissions before doing anything. Hiding a button is a courtesy; the database is the control.
Sign-in
Accounts are set up and recovered with one-time codes sent to the account’s email, and protected with a password the account holder chooses. Passwords are stored only as salted hashes by the authentication provider. Changing a password requires a fresh code, even from a signed-in device.
Payments
If a venue turns on in-app payments, cards are collected and charged by Stripe under the venue’s own Stripe account. Card numbers never touch Horreum’s servers; Horreum records the amount, the last four digits and a reference for the receipt.
The record itself
The activity log is append-only. Adds, pulls, requests and changes are recorded with the actor and the moment, and are never edited afterward. Labels carry a check digit so a mistyped code cannot be saved against the wrong bottle, and every label is registered before it can be used.
Access and operations
Production access is limited to the platform operator, uses individual credentials, and is used for support and maintenance only. Edge functions that need elevated access run server-side with keys that are never shipped to a device.
Your data, your call
A venue can request a complete export of its records at any time and receives one on leaving the platform. Members can ask their venue, or us, to correct or delete their personal information — see the privacy policy.
Reporting a concern
If you believe you have found a security issue, write to gabriel@horreum.cloud with the subject line Security. We read those first, and we will not pursue anyone who reports a problem in good faith.