Skip to content

Security Practices

Nonprofits trust us with sensitive information. Here is how we protect it, including what isn't in place yet.

Last updated: September 29, 2026

Accounts

  • Sign-in is handled by Supabase Auth. Passwords are hashed and never stored in plain text.
  • New accounts must confirm their email address before signing in.
  • Repeated sign-in and sign-up attempts from the same network address are limited.
  • Public forms include automated spam checks.

Data isolation

  • Every database table and file bucket uses row-level security, so a signed-in user can only read or change their own organization's records and files.
  • Uploaded files are stored in a private bucket and shared only through short-lived links.
  • Uploads are checked by their actual contents, not just their file name.
  • Privileged database and AI keys are never sent to the browser.

In transit and at rest

  • All traffic uses HTTPS, with HTTP Strict Transport Security enabled.
  • Data is encrypted at rest by our database and storage provider.
  • A strict Content Security Policy allows only our own scripts, each marked with a one-time code, which blocks injected scripts.
  • Pages send security headers that block framing by other sites, stop content-type sniffing, limit referrer data, and switch off browser features we don't use.

Current limitations

  • The service has not yet had an independent security audit.

Reporting a vulnerability

If you find a security issue, please email us before sharing it publicly.

Contact

Questions about this page? Email info@establis.org.