Portal data is exposed only through scoped server-side RPCs. Underlying Supabase tables are RLS-enabled and not directly readable with public credentials.
Active scans require target authorization. The scanner blocks loopback, private, link-local and cloud metadata destinations to reduce SSRF risk.
The NovGuard container runs non-root, read-only, no-new-privileges, with all Linux capabilities dropped.