Security Architecture

Last updated: September 1, 2026

Authentication

Authentication is handled through Supabase Auth, which powers email/password and OAuth (Google) sign-in flows. Passwords are hashed with industry-standard algorithms and are never stored in plaintext.

Authorization

Server-side row-level security (RLS) is enforced on your account data. Every job filter, notification rule, proposal, and channel is scoped to your user account — other users can never read or mutate your data.

API Security

All API endpoints authenticate requests and validate input. Sensitive endpoints are rate-limited, cron jobs are protected with constant-time secret comparison, and error messages never leak internal details.

Webhooks

Outbound webhook alerts include a per-channel secret (X-UpScore-Secret), and webhook URLs are validated against server-side request forgery (SSRF) patterns before being stored.

Encryption in Transit

All traffic to and from the Service is encrypted using TLS. Data stored in our database is protected at rest by our infrastructure providers.

Reporting a Vulnerability

Found a security issue? Please report it privately to security@getupscore.com rather than disclosing it publicly.