Security & Trust

We Take Security Seriously

This page is updated automatically from nightly security scans run against our production environment using industry-standard open source tools. Results are published so you can verify our security posture at any time.

Learn how this works

SSL/TLS Rating

Powered by testssl.sh

A / 96

Grade A — Cert expires 2026-07-12T17:58:16 — 1 low

Scanned May 4, 2026, 11:58 AM

Security Headers

Powered by Mozilla Observatory

A+ / 110

Grade A+ — Score: 110/100

Scanned May 4, 2026, 11:58 AM

Dependency Vulnerabilities

Powered by Trivy (Aqua Security)

PASS

0 critical, 0 high vulnerabilities

Scanned May 4, 2026, 11:58 AM

OWASP Baseline Scan

Powered by OWASP ZAP

PASS

Pass — 0 high-risk findings

Scanned May 4, 2026, 11:58 AM

Uptime & Availability

External Status Page

System uptime and availability is monitored externally and published on a dedicated status page that operates independently from our main application.

View status page

Platform Security Controls

Verified automatically from our codebase and infrastructure each night.

Encryption at Rest (AES-256)

Powered by Supabase Infrastructure

PASS

Encryption at rest confirmed — Supabase documentation verifies AES-256 encryption for all stored data

Scanned May 4, 2026, 11:58 AM

Multi-Factor Authentication

Powered by Codebase Verification

PASS

MFA implementation verified — 5 components confirmed

Scanned May 4, 2026, 11:58 AM

Role-Based Access Control

Powered by Codebase Verification

PASS

RBAC implementation verified — 6 components confirmed

Scanned May 4, 2026, 11:58 AM

Data Isolation (Row-Level Security)

Powered by Migration Analysis

PASS

21 tables verified in production database with Row-Level Security enabled

Scanned May 4, 2026, 11:58 AM

CI/CD Security Scanning

Powered by Pipeline Configuration

PASS

CI/CD security pipeline verified — SAST, secret detection, dependency scanning, and nightly dashboard scans active

Scanned May 4, 2026, 11:58 AM
Last updated: May 4, 2026 at 11:58 AM

Security Resources

We are committed to maintaining the highest security standards. If you have questions about our security practices or need to report a vulnerability, please use the resources below.

We use cookies to measure site performance and improve your experience. No data is sold to third parties. Privacy Policy