Access rules live in the database
Every table has row-level security, so the database itself checks who is asking before it returns or changes a single prompt. A bug in the app can't hand your library to someone else.
Trust
Prompts carry how your team works. Here's how Nvoka keeps them private, and what stays under your control.
Every table has row-level security, so the database itself checks who is asking before it returns or changes a single prompt. A bug in the app can't hand your library to someone else.
Owners, admins, editors and viewers, per workspace. Removing someone ends their access at once, and team prompts can't be shared by public link or published to the Public Library.
Every connection uses HTTPS. Data is stored in Supabase's managed Postgres, encrypted at rest, and the app is served from Cloudflare's network.
Sign in with Google, Apple or Microsoft, whose passwords Nvoka never sees, or with an email and password that is stored hashed. Sessions are short-lived tokens that renew themselves.
Checkout runs on Stripe, a PCI DSS Level 1 certified processor, through Link. Card numbers never touch Nvoka's servers.
Download your whole library any time, restore deleted prompts from the Trash for 30 days, and delete your account and personal data yourself in Settings.
Found something? Email ryan@heyitskenton.com with the details. We reply quickly and credit good-faith research. Please don't access, change or keep other people's data while testing.
Need a questionnaire answered or have questions about how Nvoka fits your policies? We're happy to walk through it.
Talk to us