Security

Your portfolio says what you’re about to file.

A list of product codes and lifecycle stages is competitively sensitive by nature — it sketches a company’s regulatory roadmap. We treat it that way.

How your data is protected

  • Row-level security on every table.The database’s public API surface is closed by default; all data access runs through server-side code that scopes every query to your verified identity. Your portfolio is never readable by another account, and never by the browser-side key.
  • No passwords. Sign-in is a one-time emailed link. There is no password to phish, reuse, or appear in a breach dump. Sessions are short-lived signed tokens, refreshed server-side.
  • Encryption in transit and at rest. TLS everywhere; the database (hosted on Supabase, AWS us-east-1) encrypts storage at rest.
  • No analytics scripts, no trackers, no pixels. The pages you read load no third-party JavaScript. The only open-tracking we ever do is on our own digest emails, to know whether the product is worth your inbox.
  • Ownership checks on every mutation. Adding, removing, or acting on a product verifies the session owns it — identity comes from the verified session, never from a form field.

What we store

Your email address, the product profiles you create (name, identifiers, lifecycle stage, optional manufacturer names), the matches our system computes against public FDA data, and the state of your action items. That is the complete list. See the privacy policy for the formal version.

Deleting your data

Removing a product deletes its matches and action history immediately — the cascade is enforced by the database. Deleting your account removes your subscriber record, portfolio, and personal data the same way. Email hello@regulatoryleadership.com and it happens.

What we don’t claim

FDA Radar is an early-stage product. We do not currently hold SOC 2 or ISO 27001 certification, and we won’t imply otherwise with a badge wall. If your procurement process needs specifics before then, write to us and we’ll answer directly.

Reporting a vulnerability

Security reports go to hello@regulatoryleadership.com. We read them first and answer fast, and we will credit you if you want credit.