Workspace isolation
- Agency data is scoped by workspace, and Supabase RLS tests cover client, campaign, scan, finding, evidence, intake, consent, subscription, report, HighLevel, and trust-request resources.
- Private evidence objects are stored under agency-scoped paths and are not exposed through public reports.
- Service-role ledgers are not readable or writable by browser-authenticated users.