TypoWise AI
Research News Platform

Security & Trust

Last updated: October 6, 2026

1. Overview

This page describes the security measures currently in place across typowise.site and platform.typowise.site (the "Service"), the providers we rely on, and how to report a vulnerability. Security is an ongoing program — this page is updated as our posture evolves.

2. Transport & headers

  • HTTPS everywhere — all traffic is served over TLS, with HTTP Strict Transport Security (HSTS, includeSubDomains, preload) enforced.
  • Content Security Policy — scripts are restricted to our own origin and the pinned Supabase client CDN; objects and framing are disabled.
  • Clickjacking protection — frame-ancestors 'none' and X-Frame-Options: DENY.
  • Additional headers — X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin, and a restrictive Permissions-Policy (no camera, microphone, or geolocation).

3. Authentication

  • Authentication is handled by Supabase Auth. We support email one-time codes and Google OAuth — we never store passwords.
  • Sessions use Supabase-issued tokens stored in browser local storage; signing out invalidates the session server-side.
  • OAuth redirect URIs are restricted to our registered domains.
  • Only the publishable anon API key is ever exposed to the browser. No service-role or secret keys exist in client code.

4. Application security

  • Least privilege — the frontend holds no elevated credentials; authenticated data access is governed by Supabase row-level security.
  • Pinned dependencies — third-party scripts are loaded from pinned, versioned URLs; there is no bundled dependency tree to audit beyond what is listed in our repository.
  • No third-party trackers — fonts and assets are self-hosted; no analytics or advertising pixels run on our sites.
  • Authenticated areas are unindexed — the platform console and login pages carry noindex directives.

5. AI systems

Sora, our decision model, is designed with defensive properties at the model layer, not only at the application layer:

  • Injection defense — adversarial instruction-smuggling benchmark suite at 0.000 attack success rate on our public evaluation files.
  • Tamper-evident records — every decision is emitted as a hash-chained, replayable record that can be verified independently.
  • Deterministic verdicts — identical inputs produce identical decisions, which enables audit and regression testing.

Benchmark numbers refer to our published evaluation files; methodology details are in the Benchmarks documentation.

6. Infrastructure & subprocessors

  • Vercel — hosting, TLS, DDoS protection, CDN
  • Supabase — authentication and database (row-level security, encrypted at rest)
  • Google — OAuth sign-in where used
  • OpenRouter and underlying model providers — AI inference for the Sora API

7. Reporting a vulnerability

If you believe you have found a security vulnerability in the Service, report it to support@typowise.site with steps to reproduce. Please:

  • Give us a reasonable window to investigate and remediate before public disclosure.
  • Do not access, modify, or exfiltrate data belonging to other users.
  • Do not perform denial-of-service or degrade the Service for others.

We do not currently operate a paid bug-bounty program; valid reports are acknowledged and credited with permission.

8. Data requests

For access, correction, deletion, or export of your personal data — see our Privacy Policy or email support@typowise.site.

TypoWise AI

Products

Typo-1 Platform Pricing

Research

Overview Typographic Intelligence Publications

Company

About Careers News

Legal

Terms of Service Privacy Policy Usage Policy

Contact

support@typowise.site

© 2026 TypoWise AI