How DreamSheets handles your production's data.
Written for the production accountant, the studio's IT team, or whoever has to sign off on where crew details are kept. Everything here describes how the service runs today.
Separation between productions
Each production's crew, bookings, rates and locations are kept apart in the database itself, not only in the application. Every table that holds production data has PostgreSQL row-level security switched on and forced, so a query only returns rows for productions the signed-in person belongs to.
The application connects to the database as a role that cannot bypass those rules. On top of that, the application checks membership on every request. Automated checks confirm that someone who isn't on a production can't open it or change it, and that a Viewer's changes are refused everywhere.
Access within a production
Every production has one owner. The owner invites people by email as an Editor, who can make changes, or a Viewer, who can see everything and change nothing. The owner can change someone's access or remove them at any time, and can hand ownership to another member.
- Access is enforced on the server for every change, whatever the browser sends.
- Only the owner can invite people, change access, export, wrap or delete the production.
- A wrapped production is read-only for everyone until the owner reopens it.
- Viewers can see the cost report and download PDFs. Invite people as Viewers only if they should see rates and costs.
Accounts and sign-in
- Invitation only. There is no public sign-up. People join a production through an emailed invitation.
- Invite links work once, expire after seven days, and can be revoked before they're used.
- Passwords are handled by our authentication provider, Supabase Auth. DreamSheets itself never stores them.
- Repeated failed sign-ins from the same address are locked out for fifteen minutes, per account and across accounts.
- Sessions use a single cookie that scripts on the page can't read, sent only over HTTPS, and ending after fourteen days.
Connections
DreamSheets is served over HTTPS only. Plain HTTP requests are redirected, and browsers are told to use HTTPS for the domain for a year (HSTS, including subdomains).
Pages carry a content security policy that only allows scripts from DreamSheets itself. The app loads no third-party scripts, fonts, trackers or analytics.
Requests that change something are checked for the site they came from. If the browser's Origin header, or failing that the Referer header, names any site other than DreamSheets, the request is refused. Requests that carry neither header, such as ones from command-line tools, aren't refused by this check. Anything that changes a production still needs a signed-in session, and the session cookie is marked SameSite=Lax, so browsers don't send it with a form submitted from another site.
Where data is held
Your production data is stored in the United Kingdom: the database runs in London (Supabase on AWS) and the application server with Hostinger in the UK. The database is a managed PostgreSQL service run by Supabase. Email, such as invitations and password resets, is sent through our mail provider over an encrypted connection.
Backups
Every table in the database is copied each night to a separate archive on the application server. Archives are kept for 30 days, with access limited to the account that runs DreamSheets and the server's administrators.
Activity log
Sign-ins and failed sign-ins, password changes, productions being created, wrapped, reopened and deleted, invitations, access changes, removals and changes of ownership are written to an activity log. A production's owner can see the entries for their production, with schedule edits from the last 90 days, under Manage production → Activity. Sign-ins aren't shown there.
When a production ends
The owner can wrap a production, which keeps it readable for everyone on it, or export it as a JSON file. Deleting a production removes it, with its schedule, lists and crew, from the live database straight away. It remains in the nightly backup archives until they expire, which takes up to 30 days.
Certifications
DreamSheets doesn't currently hold ISO 27001 or SOC 2 certification. If your studio has a security questionnaire, send it to support@dreamsheets.co.uk and we'll answer it.
Reporting a problem
If you think you've found a security problem, email support@dreamsheets.co.uk with what you found and how to reproduce it. Please don't test against productions that aren't yours.
Put your next production on DreamSheets.
Tell us about the job and when prep starts, and we'll be in touch.