TRUST

Security

Last updated: September 2026

Payments

✓Card details are handled entirely by Stripe, a PCI DSS Level 1 certified payment processor. Your card number never reaches Userintly's servers.
✓We store only a Stripe customer ID in our database - not any payment credentials.
✓The statement descriptor on your card statement reads “USERINTLY” so the charge is always clear.

Data in transit and at rest

✓All connections to Userintly are encrypted with TLS 1.2 or higher. HTTP requests are redirected to HTTPS.
✓Your account data is stored in Supabase (PostgreSQL), which encrypts data at rest using AES-256.
✓Row-level security is enabled on all database tables so users can only read and write their own data.

API secrets and keys

✓All third-party API keys (DataForSEO, YouTube, Anthropic, Stripe secret key) are stored as server-side environment variables in Vercel. They are never included in client-side bundles.
✓Only Supabase's public anon key and Stripe's publishable key are exposed to the browser - both are designed to be public.
✓The Anthropic API key is never logged and is only used server-side to process campaign program requests for Command-tier users.

Authentication

✓Authentication is handled by Supabase Auth, which implements bcrypt password hashing, email confirmation, and OAuth provider verification.
✓Sessions use short-lived JWTs with refresh-token rotation.
✓Rate limiting on free demand scans (3/IP/day) and AI program generation (20/user/day) is enforced server-side via Upstash Redis.

Vulnerability disclosure

If you discover a security vulnerability, please email security@userintly.com before public disclosure. We will acknowledge your report within 48 hours and work with you to resolve it responsibly. We do not currently operate a bug bounty programme, but we will publicly credit researchers who report valid issues, if they wish.