Security

Last updated: September 2026

Quibo is security-first. This page summarizes our controls, where your data lives, our sub-processors, and how to report a vulnerability. For the full Privacy Policy see /privacy; for the DPA see /dpa.

Where your data lives

  • Database, authentication and file storage: Supabase, EU (Stockholm).
  • Application servers: Vercel, EU (Frankfurt).
  • Background jobs (generation, publishing, exports): Railway, EU (Amsterdam).
  • What leaves the EU: prompts and article drafts sent to the AI, research and keyword providers, images generated for you, emails, payments, and the job queue metadata held by Inngest. Each provider is listed below with its safeguard.

Encryption

  • TLS 1.3 in transit. HSTS with includeSubDomains and the preload directive.
  • AES-256-GCM at rest for CMS credentials and Google tokens, with versioned master keys and a documented rotation procedure. Credentials are decrypted only on the server at publish time and are never returned to the browser, logged, or included in exports.
  • Postgres-managed bcrypt for password hashes.

Access control

  • Postgres row-level security on every table, gated by a JWT-injected org_id claim.
  • Service-role keys only used server-side, never exposed to the browser.
  • Account lockout after 10 failed login attempts, for 30 minutes, plus per-IP rate limits.

Application hardening

  • Nonce-based Content-Security-Policy with strict-dynamic on the application and account pages; a fixed policy on the docs and blog.
  • X-Frame-Options DENY, X-Content-Type-Options nosniff, Referrer-Policy strict-origin-when-cross-origin, Permissions-Policy minimal.
  • Every request to a customer site goes through an anti-SSRF guard: DNS resolution, private and link-local ranges blocked, redirects not followed.
  • Rate limits on login, signup, generation, exports and polling endpoints (Upstash sliding window).
  • Stripe, AppSumo and Inngest webhooks verified by signature on every request.

Audit and logging

  • Append-only audit log for logins, site connections, role changes, exports and deletions.
  • IP addresses and user agents in the audit log are scrubbed after 30 days.
  • Sentry error monitoring hosted in the EU, with PII scrubbing before events leave the server.
  • Daily automated database backups managed by Supabase.

Your data, your call

  • Self-service export: a JSON file with every record we hold for your organization.
  • Self-service deletion with a 30-day grace period. When the last member of an organization deletes their account, the organization, its sites, connector credentials, articles and files are deleted too, and any active subscription is cancelled.

Sub-processors

We process data through the following providers under DPA and SCC where applicable:

ProviderPurposeRegionSafeguard
SupabaseDatabase, authentication, file storageEU (Stockholm)DPA, EU hosting
VercelApplication hostingEU (Frankfurt)DPA, SCC
RailwayBackground job workerEU (Amsterdam)DPA, SCC
InngestJob orchestration and event queueUSDPA, SCC
AnthropicLLM (article generation)USDPA, SCC
OpenRouterLLM gatewayUSDPA, SCC
ExaWeb researchUSDPA, SCC
DataForSEOKeyword volume and difficultyUSDPA, SCC
FirecrawlBrand-profile crawlingUSDPA, SCC
fal.aiImage generationUSDPA, SCC
GoogleSearch Console API, only when you connect itUSDPA, SCC
StripePayments and taxUS/EUDPA, SCC, PCI-DSS
AppSumoLifetime deal licensing, AppSumo customers onlyUSDPA, SCC
ResendTransactional emailUSDPA, SCC
LitlyxCookieless product analyticsEUDPA, no cookies, no cross-site tracking
SentryError monitoringEU (Germany)DPA, PII scrubbing
UpstashRate limiting (Redis)EUDPA

Vulnerability disclosure

We welcome reports from security researchers. Email security@quibo.cc with details and a proof of concept. We will acknowledge within 48 hours and aim to resolve critical issues within 7 days. Responsible disclosure is rewarded; see our security.txt.

Incident response

On confirmation of a personal-data breach, we notify the relevant supervisory authority within 72 hours (GDPR Art. 33). Affected users are notified directly when the breach poses a high risk to their rights and freedoms (Art. 34).