Security

Security & Responsible Disclosure

Last updated: April 1, 2026

Our commitment to security

At Interlüde we take the security of our platform and our users seriously. We implement industry-standard security practices including HTTPS encryption, Row Level Security on our database, API rate limiting and secure authentication through Supabase.

Responsible disclosure

If you discover a security vulnerability in Interlüde, we ask that you report it to us responsibly before disclosing it publicly. We appreciate your help in keeping our platform safe.

Please report security vulnerabilities to:

Security Contact

evidence@getinterlude.app

Subject line: Security Vulnerability Report

What to include in your report

  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • Any relevant screenshots or proof of concept
  • Your contact information so we can follow up

Our commitment to researchers

  • We will acknowledge receipt of your report within 48 hours
  • We will investigate and keep you informed of our progress
  • We will not take legal action against researchers acting in good faith
  • We will credit researchers who discover valid vulnerabilities

Scope

In scope:

  • getinterlude.app and all subdomains
  • Interlüde API endpoints
  • Authentication and session management
  • User data access and privacy

Out of scope:

  • Social engineering attacks
  • Physical security
  • Third-party services (Supabase, Vercel)
  • Denial of service attacks

Security measures in place

  • HTTPS encryption on all connections
  • Row Level Security (RLS) — users only access their own data
  • API rate limiting — 60 requests per minute per IP
  • Secure authentication via Supabase Auth
  • Security headers — X-Frame-Options, CSP, HSTS and more
  • Data stored in Canada (ca-central-1 region)