Legal

Security Overview

Verified security practices for Slurp startup listings, founder accounts, payments, and vulnerability reporting.

Effective date

July 7, 2026

Operator

Slurp

Governing law

State of Montana

§01

Scope and Limitations

This Security Overview describes verified security practices for Slurp as of the effective date above. It supplements our Privacy Policy and Terms of Service.

This page is not a certification statement. Slurp is not SOC 2, ISO 27001, HIPAA, PCI DSS certified as a standalone product, or otherwise accredited unless expressly stated in a signed writing by authorized Slurp personnel.

§02

Transport, Hosting, and Headers

Slurp is served over HTTPS in production. Deployments configure security headers including Content-Security-Policy, HTTP Strict Transport Security (HSTS), and clickjacking protections compatible with Stripe Checkout and authentication providers.

Application hosting and edge delivery are provided through Vercel. Database, authentication, and object storage are provided through Supabase.

§03

Account and Session Security

User authentication is handled through established identity providers and secure session mechanisms. Magic links, passwords, and session tokens are transmitted over encrypted connections and expire according to configured policies.

Founder Dashboard access requires authenticated sessions tied to verified account ownership or authorized collaborator roles. Possession of an email address alone does not grant access to another user's Account or Listings.

§04

Listing Data and Media Storage

Listing media, submission drafts, and related assets are stored in encrypted object storage with access controls. Private drafts and unpublished submissions are not publicly listable. Published Listing pages are intentionally public as described in our Privacy Policy.

Signed URL delivery and bucket policies limit direct access to non-public assets. Retention periods are defined in our Privacy Policy.

§05

Payments

Payment card data is processed by Stripe. Slurp does not store full card numbers on its servers. Stripe maintains PCI DSS compliance for its card processing environment. Listing purchase records are stored with minimal payment metadata necessary for billing support and entitlement enforcement.

§06

Abuse Prevention and Logging

Rate limits, hashed IP addresses where configured, signed tokens, audit logging, vote integrity checks, and restricted admin access help prevent misuse. Suspicious patterns may result in temporary holds rather than silent permanent bans from weak signals alone.

Operational alerts may notify authorized personnel of anomalous failure or abuse patterns where configured.

§07

Internal Access and Personnel

Access to production systems and customer data is limited to personnel with a legitimate business need. We use role-based controls and minimize privileged access. Personnel are expected to follow confidentiality and security obligations.

§08

Incident Response

We maintain procedures to investigate suspected security incidents, contain impact, remediate vulnerabilities, and notify affected users or authorities where required by law. Notification timing and content depend on incident severity and legal obligations.

If you believe your account is compromised, contact [email protected] and rotate credentials associated with your email provider.

§09

Responsible Vulnerability Disclosure

We welcome good-faith reports of security vulnerabilities. If you believe you have found a security issue affecting Slurp, contact [email protected] with:

  • Description of the vulnerability and potential impact
  • Steps to reproduce, including URLs or request details where safe
  • Your contact information for follow-up

Please do not publicly disclose unresolved vulnerabilities, perform destructive testing, or access data belonging to other users. We aim to acknowledge reports within five (5) business days and will work with you on coordinated disclosure where appropriate.

§10

Infrastructure Providers

Primary infrastructure providers include:

  • Supabase - database, authentication, encrypted storage
  • Stripe - payments
  • Resend - transactional email
  • Vercel - hosting and delivery
  • Clerk or comparable identity providers - authentication where enabled

Each provider maintains its own security program. We evaluate providers for suitability and configure integrations to minimize data exposure.

§11

Your Security Responsibilities

You are responsible for:

  • Maintaining control of your email inbox and authentication factors
  • Submitting accurate Listing Data and reviewing public content before publication
  • Protecting Founder Dashboard access and not sharing session credentials broadly
  • Ensuring outbound links from your Listing do not expose users to harm
  • Promptly reporting suspected unauthorized access or listing impersonation
§12

Security Disclaimer

NO METHOD OF TRANSMISSION OR STORAGE IS COMPLETELY SECURE. SLURP CANNOT GUARANTEE ABSOLUTE SECURITY. YOU USE THE SERVICE AT YOUR OWN RISK. SECURITY PRACTICES DESCRIBED HERE REFLECT OUR CURRENT PROGRAM AND MAY CHANGE AS THREATS AND INFRASTRUCTURE EVOLVE.
§13

Security Contact

Security inquiries: [email protected].

This document is provided for informational purposes and does not constitute legal advice. If you have questions about these terms, contact [email protected]. For a consolidated view of all policies, see the Legal Center.