Security
Last updated: October 20, 2018
Security is a core priority at LaunchAndLoop. We implement technical, administrative, and organizational safeguards designed to protect your information and maintain the security of our platform.
While no system can guarantee absolute security, we continuously work to improve our security practices and infrastructure.
Security Measures
Encryption
- Data is encrypted both in transit and at rest.
- Sensitive credentials, API keys, and secrets are encrypted before storage.
- Our infrastructure providers use industry-standard encryption technologies, including AES-256 encryption for stored data and TLS for data transmitted over the network.
Secure Communications
- All communication with LaunchAndLoop occurs over secure HTTPS/TLS connections.
- We enforce encrypted connections between users, our servers, and supported third-party services.
Authentication
We use secure authentication mechanisms, including:
- OAuth authentication (such as Google Sign-In)
- Secure session management
- Email-based authentication
- Account verification where applicable
Access Controls
Access to internal systems is restricted using the principle of least privilege.
We implement:
- Role-based access controls
- Authentication for administrative systems
- Limited access to production environments
- Audit logging for privileged operations
Infrastructure Security
LaunchAndLoop is built on trusted cloud infrastructure and managed services, including Supabase and Vercel.
Our platform benefits from security features such as:
- Row Level Security (RLS) to restrict database access
- Encrypted database storage
- Secure cloud infrastructure
- Continuous infrastructure monitoring
- Backup and disaster recovery capabilities
- Automated security updates where applicable
Secrets Management
Sensitive credentials are protected using secure secrets management practices.
Examples include:
- Encrypted API keys
- Encrypted OAuth tokens
- Environment-based secret storage
- Restricted access to production credentials
Monitoring
We continuously monitor our systems to help detect:
- Unauthorized access attempts
- Suspicious account activity
- Infrastructure anomalies
- Service availability issues
- Potential security threats
Responsible Disclosure
We appreciate responsible disclosure from the security community.
If you believe you have discovered a security vulnerability in LaunchAndLoop, please notify us as soon as possible by emailing security@launchandloop.com.
When reporting a vulnerability, please include:
- A description of the issue
- Steps to reproduce the vulnerability
- Any supporting screenshots or proof of concept
- Your contact information for follow-up questions
Please do not publicly disclose vulnerabilities until we have had a reasonable opportunity to investigate and address the issue.
Contact
For security-related questions, vulnerability reports, or responsible disclosure inquiries, please contact: