Identity
Accounts require a confirmed email and a password of at least 12 characters containing uppercase and lowercase letters, a number, and a symbol. Sensitive password changes require recent authentication and the current password. Authenticator-app MFA can be enabled from the portal.
Data isolation
Authorization is enforced in the database with row-level security, not only hidden in the interface. Clients can access records assigned to their authenticated user ID; the designated Bright Pine administrator can support all client projects.
Least privilege
The public website uses only a publishable browser key. Anonymous visitors have no table access. Elevated database credentials are never shipped to the browser, and project tables grant only the operations needed by authenticated users.
Transport and browser protection
Traffic is encrypted over HTTPS. The site uses restrictive content, framing, referrer, MIME-sniffing, and browser-permission policies to reduce common web risks. Account pages avoid third-party advertising scripts and trackers.
User control
Clients can export active portal data, delete projects, sign out, and permanently delete their account. Authentication audit information and operational logs help investigate suspicious activity.
Report a concern
If you believe an account or the site may be at risk, email sameer.lathqani@unb.ca. Do not include passwords, authentication codes, or exploit details in an initial message.