Last updated · 21 August 2026

Security

The short version

Security at Ecomyard starts in the database, not in a policy document. Here is how your workspace data is protected in practice.

01

Workspace isolation

Every row of data carries its workspace, and the database enforces row-level security on every table: members of one workspace cannot read another workspace's data, even if application code has a bug. Sensitive operations run through audited database functions instead of broad service keys.

02

Encryption

All traffic runs over HTTPS. Data and files are encrypted at rest by our infrastructure providers, Supabase and Vercel.

03

Scoped access

Creator portals use unguessable single-purpose links: a creator sees only their own earnings, gifts and deliveries, and file uploads are locked to that creator's folder. Team access follows workspace membership, with admin-only actions for payouts and gifting.

04

Files

Uploads live in private storage buckets. The product reads them through short-lived signed URLs, never public links, and uploads are limited by size and file type.

05

Backups and availability

The database is backed up continuously by our infrastructure provider. We deploy in small increments, so problems are narrow and fast to roll back.

06

Reporting a vulnerability

Found something? Email hello@ecomyard.com with steps to reproduce. We respond quickly, fix verified issues with priority and credit reporters who want it. Please do not access other people's data while testing.

Questions about this page?

We answer within one business day.

hello@ecomyard.com