Brainback
trust · security

Security is the boring floor under everything.

Short summary of how we handle infrastructure, secrets, access, and incident response — boring on purpose.

72h disclosure
the four pillars

What holds it up.

Infra

Vercel hosting, Supabase Postgres, TLS 1.3 everywhere, encryption at rest.

Secrets

Vercel encrypted env vars. Supabase service role keys server-side only, enforced by module structure.

Access

Production data access limited to on-call engineer + one designated founder. All access logged. Zero production data on developer laptops.

RLS

Every user-owned table enforces row-level security. Tested with every migration.

Authentication

Supabase Auth handles all authentication. Magic link and Google OAuth supported. Password auth not offered — magic links are more secure by default.

Vendors and subprocessors

See our subprocessors page for a full list of vendors that process user data on our behalf, including Anthropic (for tutoring), Stripe (billing), and Vercel/Supabase (infrastructure).

Incident response

Any security incident affecting user data is disclosed to affected users within 72 hours, along with the remediation taken. Report suspected issues to security@brainback.app. PGP available on request.

Compliance

Brainback is not currently SOC 2 or HIPAA certified. We are targeting SOC 2 Type I by the end of the coming fiscal year, driven by our institutional pilot pipeline.

the numbers

Some ceilings we hold ourselves to.

72h
incident disclosure window
0
production data on laptops
100%
tables with RLS enforced
1.3
TLS version everywhere
security is downstream of paranoia — we’re happily paranoid

start now

Take back the semester you actually meant to have.

Sign up in ten seconds — magic-link email, no password to remember. Free during beta.