Security
Security & Responsible Disclosure
Last updated: April 1, 2026
Our commitment to security
At Interlüde we take the security of our platform and our users seriously. We implement industry-standard security practices including HTTPS encryption, Row Level Security on our database, API rate limiting and secure authentication through Supabase.
Responsible disclosure
If you discover a security vulnerability in Interlüde, we ask that you report it to us responsibly before disclosing it publicly. We appreciate your help in keeping our platform safe.
Please report security vulnerabilities to:
Security Contact
evidence@getinterlude.app
Subject line: Security Vulnerability Report
What to include in your report
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue
- Any relevant screenshots or proof of concept
- Your contact information so we can follow up
Our commitment to researchers
- We will acknowledge receipt of your report within 48 hours
- We will investigate and keep you informed of our progress
- We will not take legal action against researchers acting in good faith
- We will credit researchers who discover valid vulnerabilities
Scope
In scope:
- getinterlude.app and all subdomains
- Interlüde API endpoints
- Authentication and session management
- User data access and privacy
Out of scope:
- Social engineering attacks
- Physical security
- Third-party services (Supabase, Vercel)
- Denial of service attacks
Security measures in place
- HTTPS encryption on all connections
- Row Level Security (RLS) — users only access their own data
- API rate limiting — 60 requests per minute per IP
- Secure authentication via Supabase Auth
- Security headers — X-Frame-Options, CSP, HSTS and more
- Data stored in Canada (ca-central-1 region)