Skip to content
Security

Security is the product

Credentials exist to establish trust. That starts with how we protect your data — defaults on day one, not features on day 500.

Last updated: April 5, 2026

On this page

How we protect you

Security, by default

Six layers of protection, none of which require configuration.

Encryption at rest & in transit

AES-256 at rest, TLS in transit. No exceptions, no toggles.

EU data hosting

All data stored in GDPR-compliant infrastructure within the European Union.

Hashed claim tokens

256-bit single-use claim tokens, stored only as SHA-256 hashes — never in plaintext.

Row-level access controls

Postgres RLS policies enforce per-academy data isolation at the database layer.

PKCE authentication

PKCE OAuth code exchange via Supabase Auth, with email verification on signup.

Dependency scanning

Ongoing dependency and vulnerability scanning across the stack.

Infrastructure

Built on proven foundations

Supabase (PostgreSQL)

Managed Postgres with built-in auth, storage, and row-level security.

Per-tenant isolation

Row-level security policies keep every academy's data separated.

Managed backups

Automated backups with point-in-time recovery on the database layer.

Rate limiting

IP and per-certificate limits protect public verification endpoints.

Compliance status

GDPRCompliant
SOC 2Not yet pursued
ISO 27001Not yet pursued

We only list certifications we actually hold. SOC 2 and ISO 27001 are not yet pursued — we'll say so plainly until they are. Ask for our current security questionnaire any time.

Responsible disclosure

Found something? Tell us.

We value the security research community. If you discover a vulnerability, please report it responsibly — we commit to working with you to understand and resolve issues quickly.

security@truecerta.com