Security & Privacy

Current controls, planned upgrades, and claims we do not make yet

Current Security Posture

ReferCommander has real application security foundations: Supabase Auth, role checks, RLS, direct-client deny policies for server-owned tables, security headers, validation, audit logs, and provider boundaries for billing and integrations.

We are not presenting this as a formal compliance certification. Some enterprise controls are planned, some are later-stage business work, and some are only relevant if the product starts handling cardholder data or external developer access directly.

ReferCommander is a product operated by Six Ideas Technology Private Limited.

Legal entity
Six Ideas Technology Private Limited
Product
ReferCommander
Official domain
refercommander.com

Live Code-Backed Controls

Authentication and Roles

Supabase Auth, session checks, API auth wrappers, and operator workspace guards protect app routes.

  • - Supabase session refresh
  • - Role checks for admin, creator, and affiliate routes
  • - Workspace permissions for fleet actions

Database Isolation

Supabase RLS and explicit direct-client deny policies protect server-owned tables.

  • - Profiles and platform settings hardened
  • - Fleet/operator tables deny direct anon/authenticated access
  • - Server services keep reward truth

Request Hardening

The app has security headers, validation, request guards, and rate-limit helpers where routes opt in.

  • - CSP, HSTS, frame, content-type, and referrer headers
  • - Zod validation on API input
  • - Rate-limit and query guard utilities

Audit Evidence

Important admin and role actions write audit records, and quality/security gates produce reports.

  • - Admin audit-log routes and service
  • - Role-switch audit records
  • - Security scans and deploy safety checks

Payment Boundary

Billing uses hosted provider flows; reward settlement proof stays owner-paid and outside platform funding.

  • - Razorpay platform billing
  • - Stripe creator catalog connection
  • - Manual, PayPal, and UPI settlement proof records

Fleet Intake Verification

Hosted fleet candidate intake uses Authkey-backed OTP before PII submission.

  • - OTP send and verify routes
  • - Private OTP challenge table
  • - Candidate consent and intake service path

Planned or Conditional Controls

External Developer API
Relevant later

Needs versioned external contracts, scoped keys or service accounts, quotas, audit trails, replay rules, and a sandbox story.

MFA / Admin Step-Up
Useful next

Needs Supabase MFA or another central provider path, enrollment/recovery UI, and admin enforcement policy.

Formal Data Protection Program
Partly started

Consent, exports, and retention foundations exist, but formal GDPR/DPDP-style readiness needs a data map, request workflow, and evidence.

SOC 2 Type II
Not a code toggle

Relevant for enterprise sales later. It needs policies, control owners, evidence collection, vendor review, and an auditor.

PCI DSS Certification
Mostly not relevant today

Hosted Stripe/Razorpay flows mean ReferCommander should avoid card data. PCI scope changes only if the app starts handling cardholder data directly.

Incident Response Automation
Not claimed yet

Logs and deploy gates exist, but automated incident response needs runbooks, alert routing, owners, and tested escalation drills.

What We Do Not Claim Yet

Claims held back until evidence exists

  • SOC 2 Type II certification
  • PCI DSS certification
  • MFA enforced for all accounts
  • 24/7 managed threat monitoring
  • Automated incident response
  • Specific AES-256 backup or storage guarantees beyond provider-managed encryption

Responsible Reporting

Report a vulnerability

If you find a security issue, send it through the contact page with steps to reproduce, affected route, expected impact, and safe evidence. Do not include secrets or unrelated customer data.

Review cadence

Security copy should be refreshed after material auth, RLS, API, payment, compliance, or vendor changes. Claims stay tied to code evidence and operational proof.

Security First, Without Overclaiming

The current app is on a good security path for an MVP plus Fleet V1, but formal certifications and public developer access should wait until the matching product and evidence are ready.