Loading ORINEL…
High-level view of how the application is built, where data flows, and how it is deployed. No proprietary or unverifiable claims.
Last updated: March 2025
/api.OPENAI_API_KEY is set; otherwise deterministic fallbacks.NEXT_PUBLIC_SENTRY_DSN is set.Browser or client sends requests to the Next.js server. Middleware enforces auth for protected routes and applies rate limiting. API routes use Supabase with the user's session (cookies) so RLS applies; service role is used only for specific backend operations (e.g. GDPR delete, audit export with compliance key, report generation worker). No tenant data is served without passing through RLS for that user or workspace.
All application tables that hold user or workspace data have RLS policies. Users see only rows where user_id = auth.uid() or where they are members of the workspace with the required role. Workspace membership and roles (owner, admin, editor, viewer) gate create/edit/delete and billing. There is no shared in-memory state between requests; horizontal scaling is supported (see On-prem deployment and scaling docs).
The app can be run on any Node.js host (e.g. Vercel, Docker, on-prem). Environment variables configure Supabase URL/keys, optional Razorpay, OpenAI, and Sentry. Database migrations are applied separately (Supabase SQL editor or migration runner). Backups and restore are described in Data handling and in the backup/restore documentation.