Velverie Security
Action needed
Security posture
Supabase RLS enabled
Row-level security on all tables
OK
RevenueCat webhook verified
Signature validation active
OK
Sentry DSN environment only
Not hardcoded in source
OK
Anthropic API key rotation
Intentionally deferred — not urgent
Deferred
GitHub repo visibility
Private
OK
App Store Connect 2FA
Not yet verified
Check
API keys
Supabase anon key
Client-side, safe to expose
Anthropic API key
Rotation deferred
RevenueCat public key
No rotation needed
Sentry DSN
In .env only
Incident log
No incidents recorded.
security