Security at SimplyVouch

If you believe you have found a security issue in SimplyVouch, please email security@simplyvouch.com with a description of the issue, the steps to reproduce it, and any proof-of-concept material. Valid reports are acknowledged within 3 business days; high-severity findings receive a remediation plan within 10 business days.

  • Data in transit: TLS/HSTS encryption on all connections.
  • Data at rest: encrypted Supabase Postgres with server-side tenant isolation.
  • Authentication: strong passwords, optional TOTP two-factor authentication, and brute-force rate limiting.
  • Payments: no cardholder data stored; Flutterwave PCI-DSS Level 1 hosted checkout.
  • API keys: SHA-256 hashed; all actions recorded in an append-style audit log.
Home Contact us