Security
Last updated: September 2026
Quibo is security-first. This page summarizes our controls, where your data lives, our sub-processors, and how to report a vulnerability. For the full Privacy Policy see /privacy; for the DPA see /dpa.
Where your data lives
- Database, authentication and file storage: Supabase, EU (Stockholm).
- Application servers: Vercel, EU (Frankfurt).
- Background jobs (generation, publishing, exports): Railway, EU (Amsterdam).
- What leaves the EU: prompts and article drafts sent to the AI, research and keyword providers, images generated for you, emails, payments, and the job queue metadata held by Inngest. Each provider is listed below with its safeguard.
Encryption
- TLS 1.3 in transit. HSTS with
includeSubDomainsand the preload directive. - AES-256-GCM at rest for CMS credentials and Google tokens, with versioned master keys and a documented rotation procedure. Credentials are decrypted only on the server at publish time and are never returned to the browser, logged, or included in exports.
- Postgres-managed bcrypt for password hashes.
Access control
- Postgres row-level security on every table, gated by a JWT-injected
org_idclaim. - Service-role keys only used server-side, never exposed to the browser.
- Account lockout after 10 failed login attempts, for 30 minutes, plus per-IP rate limits.
Application hardening
- Nonce-based Content-Security-Policy with
strict-dynamicon the application and account pages; a fixed policy on the docs and blog. - X-Frame-Options DENY, X-Content-Type-Options nosniff, Referrer-Policy strict-origin-when-cross-origin, Permissions-Policy minimal.
- Every request to a customer site goes through an anti-SSRF guard: DNS resolution, private and link-local ranges blocked, redirects not followed.
- Rate limits on login, signup, generation, exports and polling endpoints (Upstash sliding window).
- Stripe, AppSumo and Inngest webhooks verified by signature on every request.
Audit and logging
- Append-only audit log for logins, site connections, role changes, exports and deletions.
- IP addresses and user agents in the audit log are scrubbed after 30 days.
- Sentry error monitoring hosted in the EU, with PII scrubbing before events leave the server.
- Daily automated database backups managed by Supabase.
Your data, your call
- Self-service export: a JSON file with every record we hold for your organization.
- Self-service deletion with a 30-day grace period. When the last member of an organization deletes their account, the organization, its sites, connector credentials, articles and files are deleted too, and any active subscription is cancelled.
Sub-processors
We process data through the following providers under DPA and SCC where applicable:
| Provider | Purpose | Region | Safeguard |
|---|---|---|---|
| Supabase | Database, authentication, file storage | EU (Stockholm) | DPA, EU hosting |
| Vercel | Application hosting | EU (Frankfurt) | DPA, SCC |
| Railway | Background job worker | EU (Amsterdam) | DPA, SCC |
| Inngest | Job orchestration and event queue | US | DPA, SCC |
| Anthropic | LLM (article generation) | US | DPA, SCC |
| OpenRouter | LLM gateway | US | DPA, SCC |
| Exa | Web research | US | DPA, SCC |
| DataForSEO | Keyword volume and difficulty | US | DPA, SCC |
| Firecrawl | Brand-profile crawling | US | DPA, SCC |
| fal.ai | Image generation | US | DPA, SCC |
| Search Console API, only when you connect it | US | DPA, SCC | |
| Stripe | Payments and tax | US/EU | DPA, SCC, PCI-DSS |
| AppSumo | Lifetime deal licensing, AppSumo customers only | US | DPA, SCC |
| Resend | Transactional email | US | DPA, SCC |
| Litlyx | Cookieless product analytics | EU | DPA, no cookies, no cross-site tracking |
| Sentry | Error monitoring | EU (Germany) | DPA, PII scrubbing |
| Upstash | Rate limiting (Redis) | EU | DPA |
Vulnerability disclosure
We welcome reports from security researchers. Email security@quibo.cc with details and a proof of concept. We will acknowledge within 48 hours and aim to resolve critical issues within 7 days. Responsible disclosure is rewarded; see our security.txt.
Incident response
On confirmation of a personal-data breach, we notify the relevant supervisory authority within 72 hours (GDPR Art. 33). Affected users are notified directly when the breach poses a high risk to their rights and freedoms (Art. 34).