Encrypted profile payloads
Birth and personal context payloads are encrypted before durable storage. KMS-wrapped key material is kept separate from application data and never belongs in client responses.
Data & security
Birth and personal context payloads are encrypted before durable storage. KMS-wrapped key material is kept separate from application data and never belongs in client responses.
Supabase RLS and service-only database functions enforce tenant boundaries. Private routes are authenticated and excluded from sitemap and analytics.
Rate limits, idempotency, immutable container images, redacted logs, backup/restore drills and incident alerts are verified before release.
Security controls reduce risk but cannot make any online service risk-free. Report a suspected issue through the support channel rather than sharing personal data in a public issue.