Security & Trust

We Take Security Seriously

This page is updated automatically from nightly security scans run against our production environment using industry-standard open source tools. Results are published so you can verify our security posture at any time.

Learn how this works

Scan data is more than 48 hours old. Results may not reflect the current state of our systems. Our automated scans run nightly and this page will update automatically.

SSL/TLS Rating

Powered by Qualys SSL Labs

UNKNOWN

Grade Unknown — Cert expires Unknown — 1 critical, 1 low

Scanned Mar 23, 2026, 12:07 PM

Security Headers

Powered by Mozilla Observatory

A+ / 110

Grade A+ — Score: 110/100

Scanned Mar 23, 2026, 12:07 PM

Dependency Vulnerabilities

Powered by Trivy (Aqua Security)

PASS

0 critical, 0 high vulnerabilities

Scanned Mar 23, 2026, 12:07 PM

OWASP Baseline Scan

Powered by OWASP ZAP

PASS

Pass — 0 high-risk findings

Scanned Mar 23, 2026, 12:07 PM

Uptime & Availability

External Status Page

System uptime and availability is monitored externally and published on a dedicated status page that operates independently from our main application.

View status page

Platform Security Controls

Verified automatically from our codebase and infrastructure each night.

Encryption at Rest (AES-256)

Powered by Supabase Infrastructure

PASS

Encryption at rest confirmed — Supabase documentation verifies AES-256 encryption for all stored data

Scanned Mar 23, 2026, 12:07 PM

Multi-Factor Authentication

Powered by Codebase Verification

PASS

MFA implementation verified — 5 components confirmed

Scanned Mar 23, 2026, 12:07 PM

Role-Based Access Control

Powered by Codebase Verification

PASS

RBAC implementation verified — 6 components confirmed

Scanned Mar 23, 2026, 12:07 PM

Data Isolation (Row-Level Security)

Powered by Migration Analysis

PASS

21 tables verified in production database with Row-Level Security enabled

Scanned Mar 23, 2026, 12:07 PM

CI/CD Security Scanning

Powered by Pipeline Configuration

PASS

CI/CD security pipeline verified — SAST, secret detection, dependency scanning, and nightly dashboard scans active

Scanned Mar 23, 2026, 12:07 PM
Last updated: March 23, 2026 at 12:07 PM

Security Resources

We are committed to maintaining the highest security standards. If you have questions about our security practices or need to report a vulnerability, please use the resources below.

We use cookies to measure site performance and improve your experience. No data is sold to third parties. Privacy Policy