GrowthProof
Security
An overview of the safeguards and security boundaries used to protect GrowthProof customer data.
Effective and last updated: July 31, 2026
Access control
- Supabase Auth protects sign-in and session management.
- Tenant access is based on server-side membership records, not user-editable profile metadata.
- Owner, manager, technician, and client-viewer roles are enforced in server actions and database policies.
Tenant isolation and storage
- Tenant-scoped database tables use Supabase Row Level Security.
- Evidence, tenant assets, and report PDFs are stored in private buckets.
- File access uses short-lived signed URLs and public report access is limited to published report snapshots.
- Traffic is encrypted in transit using TLS. Data-at-rest encryption and infrastructure resilience rely in part on the controls provided by Supabase, Vercel, and their infrastructure providers.
Application and operational security
- Sentry error reporting and audit logs are configured to avoid tokens, signed URLs, evidence content, and raw storage fields.
- Lemon Squeezy webhook signatures are verified and webhook processing is designed to be idempotent before subscription entitlements are updated.
- Security-sensitive events such as invitations, permission changes, evidence deletion, report publishing, and billing changes are recorded where supported by the application.
- Production secrets are stored outside the source repository and access to infrastructure should follow least-privilege and multi-factor-authentication practices.
Incident response and responsible disclosure
- Suspected incidents are investigated, contained, and remediated according to their scope and severity. Affected customers will be notified when required by applicable law or contract.
- Security reports should include the affected URL, steps to reproduce, potential impact, and a safe method for follow-up. Do not access, modify, or download data belonging to other users while researching an issue.
- Good-faith reports should be sent to the contact address below with the subject ‘Security report.’
Current limitations
- The MVP does not perform malware scanning, data loss prevention, or independent compliance certification.
- GrowthProof reports help organize evidence but do not certify regulatory or security compliance and are not legal or professional compliance advice.
- No system is completely secure. Customers remain responsible for endpoint security, account administration, lawful data collection, and choosing appropriate evidence to upload.
Contact
Questions about this policy may be sent to Shawal Kabir Chy, trading as GrowthProof at support@getgrowthproof.com.
Business address: Road 8, House 405, Block D, Bashundhara R/A, Dhaka 1229, Bangladesh