Security

How Evidlume protects the service and customer data.

This page describes safeguards implemented in the current product and the security responsibilities shared with our infrastructure providers. Evidlume does not claim SOC 2, ISO 27001, HIPAA, or PCI certification.

Authentication

Supabase Auth manages Google sign-in and sessions. Protected application pages and APIs validate the current user before returning workspace data.

Workspace isolation

Organization membership checks and database row-level security scope customer-facing records to the authenticated workspace.

Server-side credentials

AI, database administration, billing, worker, and rate-limiting credentials are stored in server environments and are not shipped in browser code.

Billing safeguards

Creem webhook signatures are verified. Event identifiers detect duplicate delivery, and failed deliveries can be retried without creating duplicate payment records.

Operational monitoring

Application errors can be reported to Sentry, while health checks and worker heartbeats provide visibility into database, queue, and worker availability.

Data protection and infrastructure

The production service is delivered over HTTPS. Identity and application data are hosted in Supabase, and payment-card processing is handled by Creem rather than Evidlume. Infrastructure-level encryption, backup, and physical controls are provided within those vendors' service boundaries.

AI processing boundary

Brand context, buyer prompts, and related audit inputs are sent to the selected AI provider or gateway. Responses are stored so reports remain traceable to evidence. Do not submit secrets, regulated data, or sensitive personal information.

Shared responsibility and compliance

Supabase and other providers protect the infrastructure they operate; Evidlume remains responsible for application access rules, data flows, provider configuration, and incident handling. A provider's certification does not make Evidlume itself certified.

Report a security issue

If you believe you have found a vulnerability, email support@evidlume.com with the affected URL, reproduction steps, and potential impact. Do not access more data than necessary, disrupt the service, or publicly disclose an active issue before it has been acknowledged.