Skip to main content

Security

Last updated: September 27, 2026

This policy was last updated on the date shown above. For questions, contact legal@creagentic.ai.

Infrastructure

CREagentic is hosted on Vercel's edge network with automatic DDoS protection. Our database is hosted on Supabase with PostgreSQL encryption at rest (AES-256) and in transit (TLS 1.3).

Authentication

We use Supabase Auth with Google sign-in and email/password sign-in. Passwords are never stored in plain text; Supabase Auth stores only salted password hashes. Optional multi-factor authentication (TOTP) is available for every account and required for administrators.

API Security

API keys are stored as SHA-256 hashes. Plaintext keys are shown once on creation and never stored. Per-minute and per-day rate limiting prevents abuse. All API traffic requires TLS.

Payment Security

All payment processing is handled by Stripe (PCI DSS Level 1 certified). We never store credit card numbers, CVVs, or full card details on our servers.

Data Isolation

The application server scopes every query to the authenticated user or organization, and row-level security is enabled on customer data tables so that direct database access is also restricted. Verification of these policies in the staging database is part of every release.

Account Protection

Accounts are limited to 2 concurrent sessions. Login fingerprinting detects account sharing across 5+ distinct locations within 7 days. Suspicious activity triggers automated alerts.

Vulnerability Reporting

If you discover a security vulnerability, please report it to security@creagentic.ai. We take all reports seriously and will respond within 48 hours.

We use cookies to improve your experience and analyze site usage. See our Privacy Policy for details.