Last updated 29 August 2026

Security

Specifics, not assurances. This is how the parts of Nia Notes that hold your notes actually work.

Isolation is the database's job

Every user-facing table has row-level security switched on, and every policy is written against the identity carried by the request itself. The application does not filter your notes out of everyone's notes — the database refuses to return anyone else's in the first place, so a bug in a query cannot become a leak.

The same is true of files. All three storage buckets are private, and their policies require the object's path to begin with the owner's own account id. There is no public URL to guess and no shared folder to wander into.

Passwords

Stored as scrypt hashes, with the cost parameters recorded alongside each hash so they can be raised later without locking anyone out of their account. The plain password is never written down, never logged, and never recoverable — which is why a forgotten one is reset rather than sent.

Sessions

Signing in issues a short-lived access token and a long-lived refresh token. The refresh token is one row in the database, is rotated every single time it is used, and is httpOnly so page scripts cannot read it.

Rotation is what makes theft detectable: if a refresh token is ever presented twice, the second attempt is treated as a replay and the entire family is revoked, signing out the device that had it. Losing a session is the correct outcome of that ambiguity.

Email links

Confirmation and password-reset links carry 32 random bytes. What the database stores is only a hash of them, they expire, and they can be spent exactly once, in a single atomic update. A used link, an expired link and a forged link are indistinguishable to whoever presents them.

Keys never reach the browser

The credentials for transcription and for the AI gateway are server-side only. When you record, the server mints a short-lived token for that one connection and hands it back; your browser opens the audio connection with it directly. The application server is not in the audio path, and the long-lived key never leaves it.

Recordings and attachments

Uploaded straight from your browser to private storage under those same policies. The note stores the object's path, never a link — links are signed for a few minutes when you open the note, so nothing that leaves our systems stays valid for long.

What we have not built yet

Two-factor authentication, and end-to-end encryption in which the server could not read a note even if it wanted to. Both are wanted; neither is here. This section exists so that this page cannot quietly become a list of only the things that went well.

Reporting something

If you find a vulnerability, tell us before you tell anyone else and we will work with you on it. We do not pursue researchers who act in good faith, stay within your own account's data, and give us a chance to fix it.

To report a vulnerability, or to ask how something works: support@tecnots.com.