Security & Support
Security overview
Production workloads run on hardened cloud infrastructure with encryption in transit (TLS 1.2+) and at rest. All user data sits behind row level security, so your history is readable by your account and nobody else's. Administrative access is restricted and logged.
Application security
We deploy strict browser security headers, rate limiting on sensitive endpoints, validation on everything user-submitted, and server-side guards on the URL fetcher so it cannot be pointed at internal infrastructure. Sign-in uses one-time email links or OAuth; Fourseat never stores passwords.
Responsible disclosure
If you believe you have found a vulnerability, email security@fourseat.dev with details and reproduction steps. We aim to acknowledge reports within 24 hours. If you conduct research in good faith and give us reasonable time to fix the issue, we will not pursue legal action.
Data handling
We process the product links you share, the verdicts generated for them, and account metadata. We retain data only as long as needed to provide the service. Request deletion at any time via hello@fourseat.dev.
Product support
For account issues or how-to help, email hello@fourseat.dev. Include the email on your account and a short description; we typically respond within one business day.
