Lufu
Security
The practical safeguards Lufu uses while the product is in beta.
Account access
Lufu uses Supabase-backed authentication for sign up, login and account access. Dashboard data is scoped to the active account so app routes only load records for the account you are working in.
Private app areas
Logged-in workspace routes such as dashboard, invoices, quotes, clients, work logs, settings and reports are blocked from indexing in robots.txt and include noindex metadata.
Safer operations
- Delete and restore actions use confirmation states.
- Settings and mutation buttons show working states so clicks feel acknowledged.
- Backup and restore tools are designed to create a safety backup before replacing data.
- Draft records can be removed, while issued billing records are handled more carefully.
Beta note
Lufu is still in beta. Security and reliability work will continue as more people use the product and the account model grows.
