Security Architecture
Last updated: September 1, 2026
Authentication
Authentication is handled through Supabase Auth, which powers email/password and OAuth (Google) sign-in flows. Passwords are hashed with industry-standard algorithms and are never stored in plaintext.
Authorization
Server-side row-level security (RLS) is enforced on your account data. Every job filter, notification rule, proposal, and channel is scoped to your user account — other users can never read or mutate your data.
API Security
All API endpoints authenticate requests and validate input. Sensitive endpoints are rate-limited, cron jobs are protected with constant-time secret comparison, and error messages never leak internal details.
Webhooks
Outbound webhook alerts include a per-channel secret (X-UpScore-Secret), and webhook URLs are validated against server-side request forgery (SSRF) patterns before being stored.
Encryption in Transit
All traffic to and from the Service is encrypted using TLS. Data stored in our database is protected at rest by our infrastructure providers.
Reporting a Vulnerability
Found a security issue? Please report it privately to security@getupscore.com rather than disclosing it publicly.