Trust
Security
We treat membership data, billing webhooks, and editorial assets as production systems. Secrets stay in Netlify environment variables; the client only receives public keys.
Practices
• TLS everywhere via Netlify
• Supabase Auth JWTs for saved reports and member audio
• Stripe webhook signature verification
• RLS on `saved_articles`
• No service-role keys in the browser bundle
Disclosure
Report vulnerabilities to security@artometrics.com (mailbox TBD). See also
Privacy and
DPA.