Kernel — every copy
This is not a shared SaaS login. Each customer receives a copy of the software and their own database. The demo below is Copperline’s copy. What is live here is real; SSO is wired to that customer’s Google, Microsoft, or Rippling when we deploy their copy.
The live site is served over TLS. Browsers, APIs, and file uploads never send data as plain HTTP in production.
The database and file bucket sit on Supabase / AWS, which encrypt disks by default. We do not invent a second lock on every table — that would break search and reports.
Login passwords are stored with bcrypt. Inbound API keys are hashed (SHA-256) and shown once. Sessions are an httpOnly JWT cookie, not a token in localStorage.
Each person is Viewer, Editor, or Admin inside CRM, Inventory, Sales, Accounting, Forecasting, HR, and Manufacturing. Super admins alone manage webhooks and API keys.
Paying customers get source and their own database. Copperline’s payroll never shares a table with another company’s payroll. That is the segregation model — not rows mixed in one SaaS database.
Google, Microsoft, and Rippling are not dummy buttons on this demo. Each customer has their own Google Workspace, Microsoft Entra, or Rippling tenant. We connect that provider in their deployed copy so employees use the same login they already have at work. Magic-link email login ships with transactional email — not on this catalog yet.
We do not list empty “enterprise encryption” cards. The live demo is password + roles; SSO is built against your identity provider in your copy.
© 2026 Freehold Systems LLC