Security
Last updated: February 21, 2026
What we protect
Your account holds your goals, your tracked time, and a read-only copy of your calendar. If you subscribe, Stripe holds the payment details and we never see them. This page lists what we do to protect the rest and how to tell us when we have got something wrong.
What we do
- Encryption in transit. Everything travels over HTTPS using TLS 1.3.
- Encryption at rest. We encrypt Google OAuth tokens with AES-256-GCM.
- Authentication. Supabase Auth issues and rotates the session tokens.
- Database. PostgreSQL with row-level security, over encrypted connections.
- Payments. Stripe processes every payment. Stripe is PCI DSS compliant, and card numbers never reach our servers.
- Dependencies. We patch them on a regular schedule.
- Input validation. We validate and sanitize anything you send us.
- Rate limiting. Every API endpoint has a ceiling to blunt abuse.
Responsible disclosure
If you have found a vulnerability, tell us before you tell anyone else and we will work it through with you. Reports are welcome from anyone, and we would rather hear about a problem early than read about it later.
How to report
Please send security reports to: security@zenova.sh
Include the following details:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Your contact information for follow-up
What we promise back
- We will acknowledge receipt of your report within 48 hours
- We will investigate and provide updates on our progress
- We will not take legal action against researchers who follow responsible disclosure
- We will credit researchers (with their permission) for validated reports
- We aim to fix critical vulnerabilities within 30 days
Scope
The following are in scope for security testing:
- https://zenova.sh and subdomains
- API endpoints at https://zenova.sh/api/*
- Mobile and desktop applications (when available)
The following are out of scope:
- Third-party services (Supabase, Stripe, Google)
- Social engineering attacks
- Physical security testing
- Denial of Service (DoS) attacks
- Testing that affects other users' data
Security headers
We implement the following security headers:
X-Frame-Options: DENY- Prevents clickjackingX-Content-Type-Options: nosniff- Prevents MIME sniffingContent-Security-Policy- Restricts resource loadingReferrer-Policy- Controls referrer information
Data protection
Our Privacy Policy covers what we collect, how long we keep it, and how to get it deleted.
Contact
For security inquiries, email us at: security@zenova.sh