Trust

Security

ViewParquet reduces exposure by keeping the default workflow in the browser and separating every optional Cloud action. This page describes current controls, not a certification or guarantee.

Local-first boundary

  • Opening and querying a device file does not upload it to ViewParquet.
  • Private remote-source credentials remain in the browser.
  • Cloud upload and Cloud conversation history require an explicit user choice.

Cloud controls

  • Private S3 buckets with public access blocked and encryption in transit and at rest
  • Short-lived signed access for exact objects and explicit Device/Cloud identities
  • Supabase Row Level Security plus server ownership checks for account data
  • Rate limits, upload reconciliation, checksums, bounded multipart uploads, and deletion workflows
  • Environment-isolated authentication, storage, billing, query results, and provider credentials

Cloud-query isolation

Each Fargate task runs one validated read-only query. The task receives a short-lived token scoped to that job and temporary AWS credentials limited to the attached source objects and its result paths. It does not receive the Supabase service role or an IAM role that can browse customer objects. Tokens expire after 20 minutes and are invalidated at terminal job status.

AI and operational security

  • BYOK keys are sent from your browser to the selected provider and are not stored by ViewParquet.
  • Managed AI requires OpenRouter Zero Data Retention routing and records only bounded usage metadata in its usage ledger.
  • Production AWS launcher access is restricted to the ViewParquet query cluster, task family, and worker roles. Workload-identity migration is tracked as a launch gate.
  • Error monitoring is scrubbed to exclude file contents, SQL, prompts, and query values.

Report a vulnerability

Send a private report to antony@kaladev.co with reproduction steps, affected URLs, impact, and a safe proof of concept. Do not access other users' data, disrupt service, run denial-of-service testing, or publicly disclose an unresolved issue. We will acknowledge a credible report and coordinate remediation and disclosure in good faith.

For privacy requests, billing issues, or ordinary product support, use the Support page.