Last updated · 21 August 2026
Security
The short version
Security at Ecomyard starts in the database, not in a policy document. Here is how your workspace data is protected in practice.
01
Workspace isolation
Every row of data carries its workspace, and the database enforces row-level security on every table: members of one workspace cannot read another workspace's data, even if application code has a bug. Sensitive operations run through audited database functions instead of broad service keys.
02
Encryption
All traffic runs over HTTPS. Data and files are encrypted at rest by our infrastructure providers, Supabase and Vercel.
03
Scoped access
Creator portals open from a personal link and a password the creator sets on their first visit: a creator sees only their own earnings, gifts and deliveries, and file uploads are locked to that creator's folder. Team access follows workspace membership, with admin-only actions for payouts and gifting.
04
Files
Creator deliveries and the files in your content hub live in private storage, and the product opens them through short-lived signed links. Images meant to be shown, like logos, avatars and brief covers, are served publicly, and their folders cannot be listed. Uploads are limited by size and file type.
05
Backups and availability
The database is backed up continuously by our infrastructure provider. We deploy in small increments, so problems are narrow and fast to roll back.
06
Reporting a vulnerability
Found something? Email hello@ecomyard.com with steps to reproduce. We respond quickly, fix verified issues with priority and credit reporters who want it. Please do not access other people's data while testing.
Questions about this page?
We answer within one business day.