Security is the product
Credentials exist to establish trust. That starts with how we protect your data — defaults on day one, not features on day 500.
Last updated: April 5, 2026
On this page
How we protect you
Security, by default
Six layers of protection, none of which require configuration.
Encryption at rest & in transit
AES-256 at rest, TLS in transit. No exceptions, no toggles.
EU data hosting
All data stored in GDPR-compliant infrastructure within the European Union.
Hashed claim tokens
256-bit single-use claim tokens, stored only as SHA-256 hashes — never in plaintext.
Row-level access controls
Postgres RLS policies enforce per-academy data isolation at the database layer.
PKCE authentication
PKCE OAuth code exchange via Supabase Auth, with email verification on signup.
Dependency scanning
Ongoing dependency and vulnerability scanning across the stack.
Infrastructure
Built on proven foundations
Supabase (PostgreSQL)
Managed Postgres with built-in auth, storage, and row-level security.
Per-tenant isolation
Row-level security policies keep every academy's data separated.
Managed backups
Automated backups with point-in-time recovery on the database layer.
Rate limiting
IP and per-certificate limits protect public verification endpoints.
Compliance status
We only list certifications we actually hold. SOC 2 and ISO 27001 are not yet pursued — we'll say so plainly until they are. Ask for our current security questionnaire any time.
Responsible disclosure
Found something? Tell us.
We value the security research community. If you discover a vulnerability, please report it responsibly — we commit to working with you to understand and resolve issues quickly.
security@truecerta.com