Security
How we protect your accounts.
The short version: we keep as little as we can, encrypt what we must keep, and never ask for your passwords.
- Secure checkout by Paddle
- Keys encrypted at rest
- No passwords, ever
- Delete anytime, yourself
- 72-hour reply to security reports
Connected accounts
When you connect a tool (for example Meta), we use its official API and never ask for your password. Keys are written server-side only and encrypted at rest with Supabase Vault.
They're decrypted only to run your automations, or to show you a stored value after you sign in. You can pause or disconnect an integration any time.
Payments
Paddle is our merchant of record. Checkout, tax, invoices, and refunds run on Paddle, and card details never touch MUNIC servers.
Access control
Sign-in runs on Supabase Auth. Every request for workspace data is checked against your membership in that workspace, so customers only see their own workspaces.
Infrastructure
The app runs on Vercel, the database on Supabase in the EU, and automations on a private server in the UK. Production traffic is HTTPS only (HSTS), with strict security headers and a content security policy.
Privacy and cookies
Nothing is sent to Meta, from your browser or our servers, until you allow ad measurement. The details are in our Privacy Policy.
Your data, your call
You can delete your account and workspace yourself from Account settings.
What we don't claim
We're a small team. We don't hold SOC 2 or ISO 27001 certification yet, and we'll say so plainly until we do.
Report a vulnerability
Email team.munic@gmail.com with "Security" in the subject. We reply to every report within 72 hours.
Please give us a reasonable time to fix an issue before disclosing it.