Security

Last updated: February 21, 2026

What we protect

Your account holds your goals, your tracked time, and a read-only copy of your calendar. If you subscribe, Stripe holds the payment details and we never see them. This page lists what we do to protect the rest and how to tell us when we have got something wrong.

What we do

  • Encryption in transit. Everything travels over HTTPS using TLS 1.3.
  • Encryption at rest. We encrypt Google OAuth tokens with AES-256-GCM.
  • Authentication. Supabase Auth issues and rotates the session tokens.
  • Database. PostgreSQL with row-level security, over encrypted connections.
  • Payments. Stripe processes every payment. Stripe is PCI DSS compliant, and card numbers never reach our servers.
  • Dependencies. We patch them on a regular schedule.
  • Input validation. We validate and sanitize anything you send us.
  • Rate limiting. Every API endpoint has a ceiling to blunt abuse.

Responsible disclosure

If you have found a vulnerability, tell us before you tell anyone else and we will work it through with you. Reports are welcome from anyone, and we would rather hear about a problem early than read about it later.

How to report

Please send security reports to: security@zenova.sh

Include the following details:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)
  • Your contact information for follow-up

What we promise back

  • We will acknowledge receipt of your report within 48 hours
  • We will investigate and provide updates on our progress
  • We will not take legal action against researchers who follow responsible disclosure
  • We will credit researchers (with their permission) for validated reports
  • We aim to fix critical vulnerabilities within 30 days

Scope

The following are in scope for security testing:

  • https://zenova.sh and subdomains
  • API endpoints at https://zenova.sh/api/*
  • Mobile and desktop applications (when available)

The following are out of scope:

  • Third-party services (Supabase, Stripe, Google)
  • Social engineering attacks
  • Physical security testing
  • Denial of Service (DoS) attacks
  • Testing that affects other users' data

Security headers

We implement the following security headers:

  • X-Frame-Options: DENY - Prevents clickjacking
  • X-Content-Type-Options: nosniff - Prevents MIME sniffing
  • Content-Security-Policy - Restricts resource loading
  • Referrer-Policy - Controls referrer information

Data protection

Our Privacy Policy covers what we collect, how long we keep it, and how to get it deleted.

Contact

For security inquiries, email us at: security@zenova.sh