Skip to main content

Security

How we protect your accounts.

The short version: we keep as little as we can, encrypt what we must keep, and never ask for your passwords.

  • Secure checkout by Paddle
  • Keys encrypted at rest
  • No passwords, ever
  • Delete anytime, yourself
  • 72-hour reply to security reports

Connected accounts

When you connect a tool (for example Meta), we use its official API and never ask for your password. Keys are written server-side only and encrypted at rest with Supabase Vault.

They're decrypted only to run your automations, or to show you a stored value after you sign in. You can pause or disconnect an integration any time.

Payments

Paddle is our merchant of record. Checkout, tax, invoices, and refunds run on Paddle, and card details never touch MUNIC servers.

Access control

Sign-in runs on Supabase Auth. Every request for workspace data is checked against your membership in that workspace, so customers only see their own workspaces.

Infrastructure

The app runs on Vercel, the database on Supabase in the EU, and automations on a private server in the UK. Production traffic is HTTPS only (HSTS), with strict security headers and a content security policy.

Privacy and cookies

Nothing is sent to Meta, from your browser or our servers, until you allow ad measurement. The details are in our Privacy Policy.

Your data, your call

You can delete your account and workspace yourself from Account settings.

What we don't claim

We're a small team. We don't hold SOC 2 or ISO 27001 certification yet, and we'll say so plainly until we do.

Report a vulnerability

Email team.munic@gmail.com with "Security" in the subject. We reply to every report within 72 hours.

Please give us a reasonable time to fix an issue before disclosing it.

Cookies: Help us spend our ad budget wisely

We're a small team. Allowing cookies lets Meta show us which Instagram and Facebook ads brought you here, so we stop paying for the ones that don't. We never sell your data. Cookie details

You can change this anytime from the footer.