Security & Trust

What we do with your data, how the platform is built, and which services sit underneath it. Everything on this page is verifiable — we list only what is actually in place.

Security overview

Tenant isolation
Access to organization data is enforced with row-level security at the database layer, filtered by membership — not left to application code.
Authentication
Accounts and sessions are managed by Supabase Auth. Administrative actions are gated by organization roles.
Payments
Payments are processed by Stripe. Card details go directly to Stripe and never touch Selva's servers.
Encryption
All traffic is encrypted in transit with TLS; data is encrypted at rest by our database provider.
Verified impact data
Impact records carry GPS coordinates and photos captured at logging time, and verification status is tracked per record — the public record is evidence, not self-declaration.

Sub-processors

Services that process data on Selva's behalf:

ServicePurpose
SupabaseDatabase, authentication, and file storage
StripePayment processing
VercelWeb hosting
MapboxMaps and geocoding
Customer.ioProduct and lifecycle email
SentryError monitoring
Google Earth EngineSatellite-imagery analysis for planting-priority data

Certifications

We publish certification status here as programmes complete — and we don't claim what we haven't finished. If your review needs a specific attestation, ask us where it stands.

Documents

Our standard terms and data-processing agreement are being finalized for click-accept checkout. Until they're published here, email us and we'll send the current versions the same day.

Request documents

Security questions?

Security questionnaires, works-council questions, or anything this page doesn't answer — write to us and a human replies within one business day.

Contact us