Last updated August 2026
What Ensite's infrastructure actually does today — not a marketing claim, the real setup.
Every organization's records are isolated at the database level with Postgres row-level security policies, not just application-layer checks — a query for another organization's data is rejected by the database itself, not merely hidden by the app.
Accounts and sessions are handled by Supabase Auth, not a custom-built login system.
Uploaded documents are held in Supabase Storage; application data lives in a managed Postgres instance in the EU-West (Ireland) region. All traffic between your browser and Ensite is encrypted over HTTPS.
A property's Grid Passport is only ever visible externally if someone on your team explicitly generates a share link for it — nothing is public by default.
For a specific security questionnaire or vendor review, contact us directly.