Built on trust, not promises.
Security claims you can actually verify — nothing overstated.
Blinds Base is multi-tenant software: many blinds and curtains businesses run on the same platform, each under their own account. That only works if your data is genuinely walled off from every other business on it — the six areas below are exactly how that separation, and everything else protecting your account, actually works.
- Tenant isolation
- Authentication & permissions
- Encryption & secrets
- Audit logs
- Deletion and export
- Locked down by default
Tenant isolation
Strict tenant isolation is enforced at both the database and application layers. Your business's data is never mixed with, or readable by, another business on the platform. Every query is scoped to your organisation's own ID, and that scoping is enforced by Postgres row-level security policies at the database itself — not only by application code that a page-level bug could bypass.
Authentication & permissions
Every account signs in through a secure authentication system. Fine-grained, per-account permission controls let a business owner grant or restrict access to any feature for any staff member. Four built-in roles — CEO, office, fitter and manufacturer — each start with a different default set of permissions, and any individual permission can be overridden for any one staff member without needing a developer.
Encryption & secrets
Third-party credentials and other secrets are encrypted at rest and are never exposed to a browser. Connected integrations have their credentials encrypted with AES-256-GCM before they ever reach the database: the Gmail Auto Booker's Google App Password and the Facebook connection's access token. The encryption key is itself never stored in that database, so a raw copy of the table alone would reveal only ciphertext.
Audit logs
Meaningful actions in your account are recorded to an append-only table that no staff account can edit or delete — who changed what, and when. A write that fails is retried automatically, and on the rare occasion it still can't be recorded, that failure is itself written to a separate record your team can review, rather than silently disappearing into a server log.
Deletion and export
Two specific things, rather than a label. Your Privacy Policy and Data Deletion instructions are published and readable without signing in to anything, and a deletion request is answered within 30 days and confirmed in writing — while your own staff can permanently erase a customer and their records from inside the platform at any time. And your data is never locked in: customers, payments, documents, reports, your price table and the audit log all export to CSV whenever you want them.
Locked down by default
Every response carries a strict Content Security Policy — no third-party scripts, no framing of the app by anyone, no plugin content — plus HTTP Strict Transport Security forcing an encrypted connection for two years across every subdomain, and headers that block MIME-sniffing and clickjacking outright. None of this is an opt-in extra: it's applied to every page and API route by default.
