Scope and Limitations
This Security Overview describes verified security practices for Slurp as of the effective date above. It supplements our Privacy Policy and Terms of Service.
This page is not a certification statement. Slurp is not SOC 2, ISO 27001, HIPAA, PCI DSS certified as a standalone product, or otherwise accredited unless expressly stated in a signed writing by authorized Slurp personnel.
Transport, Hosting, and Headers
Slurp is served over HTTPS in production. Deployments configure security headers including Content-Security-Policy, HTTP Strict Transport Security (HSTS), and clickjacking protections compatible with Stripe Checkout and authentication providers.
Application hosting and edge delivery are provided through Vercel. Database, authentication, and object storage are provided through Supabase.
Account and Session Security
User authentication is handled through established identity providers and secure session mechanisms. Magic links, passwords, and session tokens are transmitted over encrypted connections and expire according to configured policies.
Founder Dashboard access requires authenticated sessions tied to verified account ownership or authorized collaborator roles. Possession of an email address alone does not grant access to another user's Account or Listings.
Listing Data and Media Storage
Listing media, submission drafts, and related assets are stored in encrypted object storage with access controls. Private drafts and unpublished submissions are not publicly listable. Published Listing pages are intentionally public as described in our Privacy Policy.
Signed URL delivery and bucket policies limit direct access to non-public assets. Retention periods are defined in our Privacy Policy.
Payments
Payment card data is processed by Stripe. Slurp does not store full card numbers on its servers. Stripe maintains PCI DSS compliance for its card processing environment. Listing purchase records are stored with minimal payment metadata necessary for billing support and entitlement enforcement.
Abuse Prevention and Logging
Rate limits, hashed IP addresses where configured, signed tokens, audit logging, vote integrity checks, and restricted admin access help prevent misuse. Suspicious patterns may result in temporary holds rather than silent permanent bans from weak signals alone.
Operational alerts may notify authorized personnel of anomalous failure or abuse patterns where configured.
Internal Access and Personnel
Access to production systems and customer data is limited to personnel with a legitimate business need. We use role-based controls and minimize privileged access. Personnel are expected to follow confidentiality and security obligations.
Incident Response
We maintain procedures to investigate suspected security incidents, contain impact, remediate vulnerabilities, and notify affected users or authorities where required by law. Notification timing and content depend on incident severity and legal obligations.
If you believe your account is compromised, contact [email protected] and rotate credentials associated with your email provider.
Responsible Vulnerability Disclosure
We welcome good-faith reports of security vulnerabilities. If you believe you have found a security issue affecting Slurp, contact [email protected] with:
- Description of the vulnerability and potential impact
- Steps to reproduce, including URLs or request details where safe
- Your contact information for follow-up
Please do not publicly disclose unresolved vulnerabilities, perform destructive testing, or access data belonging to other users. We aim to acknowledge reports within five (5) business days and will work with you on coordinated disclosure where appropriate.
Infrastructure Providers
Primary infrastructure providers include:
- Supabase - database, authentication, encrypted storage
- Stripe - payments
- Resend - transactional email
- Vercel - hosting and delivery
- Clerk or comparable identity providers - authentication where enabled
Each provider maintains its own security program. We evaluate providers for suitability and configure integrations to minimize data exposure.
Your Security Responsibilities
You are responsible for:
- Maintaining control of your email inbox and authentication factors
- Submitting accurate Listing Data and reviewing public content before publication
- Protecting Founder Dashboard access and not sharing session credentials broadly
- Ensuring outbound links from your Listing do not expose users to harm
- Promptly reporting suspected unauthorized access or listing impersonation
Security Disclaimer
Security Contact
Security inquiries: [email protected].