Andreas Digital AgencyTechnology. Systems. Growth.
← Back to News

Technology News

ADA builds security-first administration into its website

The ADA admin environment now uses MFA, AAL2 enforcement, row-level security, private recruitment storage and activity logging.
PublishedAugust 20264 min read

Security has become part of the launch architecture of the ADA main website rather than an afterthought added once the public pages were complete.

The administrative environment requires a valid Supabase session, an active ADA administrator profile and a second-factor verification step before access is granted. Sensitive database operations are further restricted using row-level security and AAL2-aware policies.

Career documents are stored in a private bucket with file-type and size restrictions. Authorised administrators receive short-lived signed links when reviewing applications instead of exposing permanent public file URLs.

Important administrative changes are also written to an audit table by database triggers. This gives ADA a traceable record of actions such as recruitment status changes, including the administrator, time, changed fields and authentication assurance level.