Security

MechanIQ is built tenant-first. Workshop data is isolated by design, not by configuration.

Security pillars

Row-Level Security

Every entity is protected by RLS. A user can only read or modify records within their own workshops and organisations.

Last-owner protection

Organisations can never lose their last active owner — removal, downgrade and deactivation are guarded.

created_by_id controls

Ownership is anchored to the creating user; spoofed ownership is rejected on create and update.

Tenant isolation

Workshops and organisations are strictly isolated. Private knowledge never leaks across tenants.

MechanIQ does not claim compliance certifications it has not obtained. Public website access does not create a path to private application entities — public routes are separate from authenticated application routes.