Kernel — every copy

Security & access

This is not a shared SaaS login. Each customer receives a copy of the software and their own database. The demo below is Copperline’s copy. What is live here is real; SSO is wired to that customer’s Google, Microsoft, or Rippling when we deploy their copy.

Live in this demoPassword login + Team roles

Sign in as the demo user, then open Team. That is the permission model you click through today: who can view or edit each module, and who is a super admin.

HTTPS in transit

The live site is served over TLS. Browsers, APIs, and file uploads never send data as plain HTTP in production.

Encryption at rest

The database and file bucket sit on Supabase / AWS, which encrypt disks by default. We do not invent a second lock on every table — that would break search and reports.

Passwords and API keys hashed

Login passwords are stored with bcrypt. Inbound API keys are hashed (SHA-256) and shown once. Sessions are an httpOnly JWT cookie, not a token in localStorage.

Per-module roles

Each person is Viewer, Editor, or Admin inside CRM, Inventory, Sales, Accounting, Forecasting, HR, and Manufacturing. Super admins alone manage webhooks and API keys.

One database per customer copy

Paying customers get source and their own database. Copperline’s payroll never shares a table with another company’s payroll. That is the segregation model — not rows mixed in one SaaS database.

Company sign-in (SSO)

Google, Microsoft, and Rippling are not dummy buttons on this demo. Each customer has their own Google Workspace, Microsoft Entra, or Rippling tenant. We connect that provider in their deployed copy so employees use the same login they already have at work. Magic-link email login ships with transactional email — not on this catalog yet.

  • Google — in the customer copy
  • Microsoft — in the customer copy
  • Rippling — in the customer copy
  • Magic link — in the customer copy

What we change after you buy

  • Google, Microsoft (Entra), or Rippling sign-in against that customer’s own identity provider
  • Magic-link login once email is on (invite and “sign in without a password”)
  • Hide whole modules from people who should not see them (today a missing role still lets them view)
  • Extra field locks on SSN, bank account, or similar — only where the customer actually stores that

We do not list empty “enterprise encryption” cards. The live demo is password + roles; SSO is built against your identity provider in your copy.

© 2026 Freehold Systems LLC