Trust Center — Security at Profit Bid
Profit Bid protects merchant ads, store credentials, and platform accounts with layered controls across authentication, isolation, encryption, monitoring, and recovery. This page summarizes our public security posture for customers and prospects.
Core controls
- Authentication & MFA — Supabase Auth; MFA required for app, agency, onboarding, and platform admin APIs.
- Multi-tenant isolation — Organization membership, RLS, and soft-suspend for incident isolation without hard delete.
- Platform admin hardening — Separate
admin_users, IP allowlist, and MFA. - Secrets — Store credentials encrypted (AES-256-GCM); service-role secret tables; no plaintext credentials in production by default.
- Webhook integrity — HMAC or platform signatures on supported store integrations.
- Detection — Security audit log, rate limits, IP auto-block, email/Slack alerts, admin Security Center.
- Recovery — Daily scheduled database backups; RTO ≤ 4 hours; RPO ≤ 24 hours.
- Supply chain — CI dependency audit, Dependabot, CodeQL, SBOM at release.
Compliance roadmap
- SOC 2 Type II — Primary commercial attestation (observation window in progress; report available under NDA when issued).
- ISO 27001 — ISMS light in place; Stage 1 readiness targeted within the 12-month program.
- GDPR — DPA available at /dpa; RoPA and DPIA maintained internally.
Attestations & reports
When issued, the SOC 2 Type II report and executive pen-test summaries are available to enterprise customers under NDA. Contact security@profit-bid.com to request access.
Data residency
Primary application database and Auth are hosted in the European Union (Supabase EU). Processing by subprocessors may involve additional regions under appropriate transfer mechanisms (see DPA / SCCs).
Subprocessors
| Vendor | Role |
|---|---|
| Supabase | Database, Auth, Storage |
| Vercel | Application hosting / edge |
| Stripe | Billing & payments |
| Resend | Transactional email |
| Inngest | Background jobs / workflows |
Material changes to this list are reflected here and notified per enterprise DPA terms.
Vulnerability disclosure
Report security issues to security@profit-bid.com. See also /.well-known/security.txt.
Related
Last updated: 2026-07-23






