Skip to main content
FeaturesPricingDocs
Sign in

Security

Last updated: July 18, 2026

Security at SupDesk

We take the security of our platform and your data seriously. SupDesk is built with security-first practices across infrastructure, application design, and operational processes. This page describes the measures we take to protect your data.

Infrastructure Security

SupDesk is hosted on Cloudflare and Supabase, both of which provide enterprise-grade infrastructure security. Cloudflare provides DDoS protection, a web application firewall (WAF), and a global CDN with automatic SSL/TLS termination. Supabase manages our PostgreSQL database with automated backups, point-in-time recovery, and encrypted storage. All infrastructure runs in SOC 2-compliant data centers.

Authentication & Access Control

Authentication is handled by Supabase Auth with secure session management. We enforce role-based access control (Owner, Admin, Member) across all projects and workspaces. API keys are project-scoped and can be revoked at any time. We never store or have access to user passwords — authentication is managed entirely by Supabase's identity infrastructure.

Data Protection & Encryption

  • •Encryption in transit: All data is transmitted over TLS 1.2 or higher. HTTP traffic is automatically redirected to HTTPS.
  • •Encryption at rest: Database storage and file attachments are encrypted at rest using AES-256 encryption, managed by our infrastructure providers.
  • •Data isolation: Each project's data is logically isolated. API keys and database queries are scoped to individual projects.

Vulnerability Disclosure

We encourage responsible disclosure of security vulnerabilities. If you discover a security issue, please report it privately by emailing security@rabinapps.com. Do not disclose the issue publicly until it has been addressed. We commit to acknowledging reports within 48 hours, providing an initial assessment within 7 days, and targeting a patch release within 30 days for confirmed vulnerabilities.

Breach Notification

In the event of a data breach affecting user personal information, we follow a documented incident response process in compliance with GDPR Article 33 and applicable US state breach notification laws. This includes detection and containment within 24 hours, internal assessment within 48 hours, regulatory notification within 72 hours, and user notification without undue delay.

Compliance Roadmap

We are committed to achieving SOC 2 Type II and ISO 27001 compliance. These certifications are actively on our roadmap and represent our investment in meeting industry-standard security and compliance frameworks. As we work toward these goals, we continue to implement the security controls and practices that underpin these standards.

Payment Processing

SupDesk uses Stripe to process payments and does not store personal credit card information for any of our customers. Stripe is a certified PCI Service Provider Level 1, which is the highest level of certification in the payments industry.

Contact

If you have questions about our security practices or want to report a vulnerability, please reach out.

You can contact us at security@rabinapps.com.

Feedback & app console for solo devs and small teams.

© 2026 Rabin Apps LLC

Product

  • Features
  • Pricing
  • Feedback Board
  • Changelog
  • Private Messaging
  • Beta Testing
  • Waitlist

Legal

  • Terms
  • Privacy
  • Cookies
  • Do Not Sell My Data
  • Security

Resources

  • Docs

Company

  • About
  • Contact
System Status