Security

Your drawings, protected

Not a feature we bolt on. It's how Notch stores, isolates, and serves your data.

Encrypted in transit & at rest

All traffic runs over TLS, and your drawings and data are encrypted at rest in our database and storage.

Tenant isolation

Every workspace's data is isolated and enforced at the database layer with row-level security — not just in application code.

Single sign-on

Sign in with Google or Microsoft. Authentication is handled by a dedicated, industry-standard identity provider.

Trusted infrastructure

Notch runs on Vercel and Supabase (managed Postgres), built on the same cloud platforms that power large-scale apps.

Least-privilege access

App requests run scoped to the signed-in user; elevated service access is reserved for narrow, audited background tasks.

Backups & version history

Your database is backed up regularly, and every document keeps a version history so changes are recoverable.

Have a security question?

We're happy to walk your team through how Notch handles data. Responsible disclosure is welcome too.

security@notch.build