Security

Security is foundational to RefStack. We manage financial data (clicks, conversions, and commissions) on behalf of our customers. This page describes our security practices and how to report vulnerabilities.

Security Practices

Encryption in Transit

All data is transmitted over HTTPS/TLS. HTTP requests are automatically redirected to HTTPS. HSTS headers enforce secure connections.

Encryption at Rest

All data is stored in Supabase (managed PostgreSQL on AWS), which encrypts data at rest using AES-256.

Row-Level Security

Every database table has Row-Level Security (RLS) policies enforced at the database layer. Tenants cannot access each other's data, and affiliates can only access their own records, even if application-level checks fail.

API Authentication

Public API endpoints (/api/v1/*) require a per-tenant API key passed in the Authorization header. Keys are generated using cryptographically secure random bytes (crypto.getRandomValues).

Webhook Verification

Server-to-server conversion events are verified using HMAC-SHA256 signatures computed with a tenant-specific API secret. Signature comparison uses timing-safe equality to prevent timing attacks.

Rate Limiting

Authentication endpoints are rate-limited to 10 requests per minute. Tracking endpoints are limited to 100 requests per hour per IP. Password reset is limited to 3 requests per hour.

Input Validation

All external input (API requests, form submissions, webhook payloads) is validated with Zod schemas before processing. Malformed or out-of-range inputs are rejected with generic error messages.

Security Headers

All responses include security headers: Strict-Transport-Security, X-Frame-Options (DENY), X-Content-Type-Options (nosniff), Referrer-Policy, and Content-Security-Policy.

Role-Based Access Control

The platform enforces two roles: tenant_admin and affiliate. Access to admin routes is verified at both the middleware and layout level. Affiliates cannot access admin pages or other affiliates' data.

Cloudflare Infrastructure

The Platform is hosted on Cloudflare Workers, providing DDoS protection, global edge network, and automatic TLS certificate management.

Responsible Disclosure

We welcome reports from security researchers. If you discover a vulnerability in RefStack, please report it responsibly before public disclosure.

How to Report

Email security@refstack.io with:

  • A description of the vulnerability
  • Steps to reproduce (proof of concept if available)
  • Affected components or URLs
  • Potential impact

Our Commitments

  • We will acknowledge your report within 72 hours
  • We will keep you informed of our progress toward a fix
  • We will not take legal action against researchers acting in good faith
  • We ask that you allow us reasonable time to patch before any public disclosure

Out of Scope

  • Denial-of-service attacks
  • Social engineering of RefStack employees
  • Automated scanner findings without demonstrated impact
  • Rate limiting bypass without demonstrated harm

Contact

Security reports and questions: security@refstack.io