Supercurve
Pricing
Sign inStart free
Pricing
Sign inStart free
Security

Security is infrastructure, not a feature.

We treat your data the way we treat our own: with paranoia, redundancy, and zero tolerance for shortcuts.

AES-256
Encryption at rest
TLS 1.3
Encryption in transit
0
Known breaches
Security controls

Encryption at Rest

All client data is encrypted at rest with AES-256 through our managed database platform, using cloud-provider-managed keys. Disk-level encryption is enabled by default across all production systems.

AES-256

Encryption in Transit

All traffic is encrypted in transit: TLS 1.3 where supported and never below TLS 1.2. We enforce HTTPS across all endpoints and reject connections using older, insecure protocols.

TLS 1.3

OAuth Tokens & Scopes

Integration credentials are stored server-side only, encrypted at rest, and never sent to the browser. We request the narrowest OAuth scopes each feature needs (read-only wherever possible), delete stored credentials the moment you disconnect an integration, and you can revoke access from the provider's own account settings at any time.

Read-only by default

Access Control

We enforce role-based access control (RBAC) with the principle of least privilege. Access to production systems is restricted to authorized staff and scoped to what each role requires.

Least privilege

Vulnerability Management

We run continuous automated dependency and vulnerability scanning across our systems, and remediate findings on a severity-prioritized basis.

Continuous

Data Residency

Customer data is stored in the United States: the primary database runs on Supabase (hosted on AWS), background workers run on Google Cloud, and the web application is served by Vercel. Data is not replicated outside these providers. If you have specific residency or compliance requirements, talk to us before onboarding.

United States

Payment Security

All payments are processed by Stripe, a certified PCI DSS Level 1 provider. Card numbers never touch Supercurve's servers; we store only billing status and invoice metadata.

PCI DSS via Stripe

Vendor Risk

All sub-processors and third-party vendors are reviewed for security posture before engagement. We maintain a current list of sub-processors and notify clients of material changes. Vendors with access to client data must meet our minimum security baseline.

ISO 27001 minimum
Responsible disclosure

Found a vulnerability?

We take security reports seriously and respond to all credible submissions. If you've identified a vulnerability in our platform or infrastructure, please report it to us privately. We commit to acknowledging reports within 24 hours and providing a status update within 5 business days.

We do not take legal action against researchers who report vulnerabilities in good faith and give us a reasonable opportunity to remediate before public disclosure. We offer recognition and, for critical findings, financial rewards at our discretion.

security@supercurve.ai
Supercurve

The AI teammate for marketing.

Product

  • SEO
  • AI search (GEO)
  • Content
  • Social
  • Competitor monitoring
  • Site health
  • Pricing

Solutions

  • B2B SaaS
  • Ecommerce
  • DTC brands
  • AI startups
  • Agencies
  • All solutions

Resources

  • Blog
  • Guides
  • Glossary
  • Compare

Company

  • About
  • Careers
  • Contact
  • Security

© Supercurve. All rights reserved.

PrivacyTermsSecurity