Security & Trust
Last updated: October 6, 2026
1. Overview
This page describes the security measures currently in place across typowise.site and platform.typowise.site (the "Service"), the providers we rely on, and how to report a vulnerability. Security is an ongoing program — this page is updated as our posture evolves.
2. Transport & headers
- HTTPS everywhere — all traffic is served over TLS, with
HTTP Strict Transport Security (HSTS,
includeSubDomains, preload) enforced. - Content Security Policy — scripts are restricted to our own origin and the pinned Supabase client CDN; objects and framing are disabled.
- Clickjacking protection —
frame-ancestors 'none'andX-Frame-Options: DENY. - Additional headers —
X-Content-Type-Options: nosniff,Referrer-Policy: strict-origin-when-cross-origin, and a restrictive Permissions-Policy (no camera, microphone, or geolocation).
3. Authentication
- Authentication is handled by Supabase Auth. We support email one-time codes and Google OAuth — we never store passwords.
- Sessions use Supabase-issued tokens stored in browser local storage; signing out invalidates the session server-side.
- OAuth redirect URIs are restricted to our registered domains.
- Only the publishable anon API key is ever exposed to the browser. No service-role or secret keys exist in client code.
4. Application security
- Least privilege — the frontend holds no elevated credentials; authenticated data access is governed by Supabase row-level security.
- Pinned dependencies — third-party scripts are loaded from pinned, versioned URLs; there is no bundled dependency tree to audit beyond what is listed in our repository.
- No third-party trackers — fonts and assets are self-hosted; no analytics or advertising pixels run on our sites.
- Authenticated areas are unindexed — the platform
console and login pages carry
noindexdirectives.
5. AI systems
Sora, our decision model, is designed with defensive properties at the model layer, not only at the application layer:
- Injection defense — adversarial instruction-smuggling benchmark suite at 0.000 attack success rate on our public evaluation files.
- Tamper-evident records — every decision is emitted as a hash-chained, replayable record that can be verified independently.
- Deterministic verdicts — identical inputs produce identical decisions, which enables audit and regression testing.
Benchmark numbers refer to our published evaluation files; methodology details are in the Benchmarks documentation.
6. Infrastructure & subprocessors
- Vercel — hosting, TLS, DDoS protection, CDN
- Supabase — authentication and database (row-level security, encrypted at rest)
- Google — OAuth sign-in where used
- OpenRouter and underlying model providers — AI inference for the Sora API
7. Reporting a vulnerability
If you believe you have found a security vulnerability in the Service, report it to support@typowise.site with steps to reproduce. Please:
- Give us a reasonable window to investigate and remediate before public disclosure.
- Do not access, modify, or exfiltrate data belonging to other users.
- Do not perform denial-of-service or degrade the Service for others.
We do not currently operate a paid bug-bounty program; valid reports are acknowledged and credited with permission.
8. Data requests
For access, correction, deletion, or export of your personal data — see our Privacy Policy or email support@typowise.site.