Security
MechanIQ is built tenant-first. Workshop data is isolated by design, not by configuration.
Security pillars
Row-Level Security
Every entity is protected by RLS. A user can only read or modify records within their own workshops and organisations.
Last-owner protection
Organisations can never lose their last active owner — removal, downgrade and deactivation are guarded.
created_by_id controls
Ownership is anchored to the creating user; spoofed ownership is rejected on create and update.
Tenant isolation
Workshops and organisations are strictly isolated. Private knowledge never leaks across tenants.
MechanIQ does not claim compliance certifications it has not obtained. Public website access does not create a path to private application entities — public routes are separate from authenticated application routes.