Active
Identity
Supabase Auth + database RLS
SECURITY COMMAND CENTER
Account security combines identity, device trust, step-up controls, audit evidence, risk decisions and a restricted intelligence pipeline. User-facing controls never write directly to privileged threat-intelligence datasets.
CONTROL MATRIX
Active
Supabase Auth + database RLS
Required
Step-up / policy boundary
Ready
Account freeze state
Backend only
Restricted ingestion pipeline
Backend only
Versioned model + evidence
Architecture
Asset Passport + risk signals
ANTI-FRAUD DATA PLANE
The platform now has restricted tables for security intelligence, derived risk features, versioned risk decisions and security cases. They are not seeded with invented “million-row” data; production intelligence must come from verified providers, telemetry and approved internal sources.
ANTI-CYBER DATA PLANE
Threat indicators, device trust and risk evidence are distinct from account preferences. This prevents a user-facing setting from becoming an authorization bypass.
CRYPTO ASSET SECURITY
Crypto Bank has an asset registry and risk-signal foundation for contract, liquidity, concentration, operational and other evidence before capabilities are granted.