A-02Platform

Per-client reporting, isolated in the database.

Your traffic, your sources, your enquiries, behind your own login. One client can never see another.

Next.js 15SupabaseUmamiBehind a login

A-02 analytics portal, demonstration tenant The analytics portal overview: visitors, page views, enquiries and enquiry rate across the top, a thirty-day visitors chart, then traffic sources, most-read routes and a list of enquiries.

Captured, not drawn. The real tenants sit behind a per-client login and hold that client's actual traffic, so this is a demonstration tenant running on a seeded synthetic fixture. The layout is the shipped one. The numbers are invented, and they are invented rather than borrowed from a client because a screenshot is not worth someone else's data. Open it full size.

  • IsolationRow-level security per tenant, one access choke-point. A request naming another tenant falls back to the viewer's own.
  • ControlsServer-only API wrapper so the key never reaches the browser, per-request nonce CSP, rate limiting, Zod validation.
  • SurfaceNo public sign-up. Generic auth errors, so the login cannot be used to enumerate users.
  • Written downA security document plus OWASP Web and OWASP LLM threat maps, kept in the repository.
schematic, how a request is isolated A-02 ANALYTICS PORTAL ONE CLIENT AT A TIME CLIENTS CLIENT 01 ROW-LEVEL SESSIONS 24,118 ENQUIRIES 311 LCP P75 1.4s TRAFFIC BY WEEK SOURCES SEARCH DIRECT REFERRAL BLOG SOCIAL

Drawn. The isolation itself has no screen to photograph: it is a row-level policy in the database, so this is the shape of it rather than a capture of it.