Who can access a client file
Portal logins are role-gated. Clients see only their company. Staff see assigned accounts. Super-admins are listed in a server-only allow-list, not inferred from the browser.
Trust
EPR work is evidence. This page is the short version of who can see it, how we log access, and how a third party can verify a certificate.
Portal logins are role-gated. Clients see only their company. Staff see assigned accounts. Super-admins are listed in a server-only allow-list, not inferred from the browser.
“Login as user” is restricted to an authenticated super-admin session. Magic links are audited. Support will never ask you to share a password.
Public verification at /verify shows masked GSTIN, registered categories, and filing status. Recyclers cannot list EPR credits with an expired or missing CPCB certificate.
Application data is stored in Supabase (Postgres in the project region configured for production). Backups and access follow that project’s controls. We do not sell compliance files.
IAM actions (invite, ban, role change, impersonation) write to an audit log with actor, target, and timestamp. Payment webhooks are signature-checked. Cron jobs require a secret.