We take the security of your data seriously. Learn about our comprehensive approach to protecting your business information and maintaining trust.
Industry-standard authentication with bcrypt password hashing and secure JWT sessions.
All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3.
Authenticated API routes with schema validation on request bodies and signature verification on inbound webhooks.
Every query is scoped to your project through server-side access checks. No client ever queries the database directly.
Hosted on Supabase and Vercel, with managed Postgres backups provided by Supabase.
Built with GDPR and SOC 2 principles in mind. We are not currently SOC 2 certified.
We review the codebase for security issues as part of ongoing development. Independent third-party penetration testing is planned, not yet completed.
Changes go through type checking, linting, and review before they ship. Automated dependency and security scanning is being rolled out.
Application errors and exceptions are captured continuously via Sentry so failures surface quickly.
Your data lives in managed Postgres on Supabase, with backup and recovery handled by Supabase at our plan level.
Access is scoped per project: you reach only the projects your account belongs to. Finer-grained roles within a project are on the roadmap.
We have documented procedures for responding to security incidents with clear communication protocols.
If you have security concerns or want to report a vulnerability, please contact our security team.
Contact Security Team