Security
Security is foundational to RefStack. We manage financial data (clicks, conversions, and commissions) on behalf of our customers. This page describes our security practices and how to report vulnerabilities.
Security Practices
Encryption in Transit
All data is transmitted over HTTPS/TLS. HTTP requests are automatically redirected to HTTPS. HSTS headers enforce secure connections.
Encryption at Rest
All data is stored in Supabase (managed PostgreSQL on AWS), which encrypts data at rest using AES-256.
Row-Level Security
Every database table has Row-Level Security (RLS) policies enforced at the database layer. Tenants cannot access each other's data, and affiliates can only access their own records, even if application-level checks fail.
API Authentication
Public API endpoints (/api/v1/*) require a per-tenant API key passed in the Authorization header. Keys are generated using cryptographically secure random bytes (crypto.getRandomValues).
Webhook Verification
Server-to-server conversion events are verified using HMAC-SHA256 signatures computed with a tenant-specific API secret. Signature comparison uses timing-safe equality to prevent timing attacks.
Rate Limiting
Authentication endpoints are rate-limited to 10 requests per minute. Tracking endpoints are limited to 100 requests per hour per IP. Password reset is limited to 3 requests per hour.
Input Validation
All external input (API requests, form submissions, webhook payloads) is validated with Zod schemas before processing. Malformed or out-of-range inputs are rejected with generic error messages.
Security Headers
All responses include security headers: Strict-Transport-Security, X-Frame-Options (DENY), X-Content-Type-Options (nosniff), Referrer-Policy, and Content-Security-Policy.
Role-Based Access Control
The platform enforces two roles: tenant_admin and affiliate. Access to admin routes is verified at both the middleware and layout level. Affiliates cannot access admin pages or other affiliates' data.
Cloudflare Infrastructure
The Platform is hosted on Cloudflare Workers, providing DDoS protection, global edge network, and automatic TLS certificate management.
Responsible Disclosure
We welcome reports from security researchers. If you discover a vulnerability in RefStack, please report it responsibly before public disclosure.
How to Report
Email security@refstack.io with:
- A description of the vulnerability
- Steps to reproduce (proof of concept if available)
- Affected components or URLs
- Potential impact
Our Commitments
- We will acknowledge your report within 72 hours
- We will keep you informed of our progress toward a fix
- We will not take legal action against researchers acting in good faith
- We ask that you allow us reasonable time to patch before any public disclosure
Out of Scope
- Denial-of-service attacks
- Social engineering of RefStack employees
- Automated scanner findings without demonstrated impact
- Rate limiting bypass without demonstrated harm
Contact
Security reports and questions: security@refstack.io