Controls are evaluated on the server, not implied by the interface.
A verified identity is only the start. Company membership, status, role permissions, resource scopes, feature entitlements, limits, and workflow state are checked again for every sensitive action.
Identity
Supabase email/password identitySingle-use email verification and recovery linksHttpOnly, Secure, SameSite session cookiesNo ChatGPT identity dependency
Tenant isolation
Active company accepted only after membership validationCompany ID carried through every business queryTenant-specific object keys for documentsNo authorization from client-provided metadata
Authorization
Role-to-permission mappingResource scopesFeature and plan entitlementsPayroll separation of duties
Evidence and recovery
Actor, company, target, reason, and correlation audit contextHashed source network identifierIdempotency for payroll preparationDocumented backup, restore, and incident procedures
Current release: production-oriented sandbox
PayUp Hub does not debit accounts, send deposits, calculate authoritative taxes, file returns, remit funds, or replace professional payroll and legal review. Those actions require configured regulated providers and launch approval.