Security & Privacy
Current controls, planned upgrades, and claims we do not make yet
Current Security Posture
ReferCommander has real application security foundations: Supabase Auth, role checks, RLS, direct-client deny policies for server-owned tables, security headers, validation, audit logs, and provider boundaries for billing and integrations.
We are not presenting this as a formal compliance certification. Some enterprise controls are planned, some are later-stage business work, and some are only relevant if the product starts handling cardholder data or external developer access directly.
Company Details
ReferCommander is a product operated by Six Ideas Technology Private Limited.
- Legal entity
- Six Ideas Technology Private Limited
- Product
- ReferCommander
- Official domain
- refercommander.com
- Contact
- contact@refercommander.com
Live Code-Backed Controls
Authentication and Roles
Supabase Auth, session checks, API auth wrappers, and operator workspace guards protect app routes.
- - Supabase session refresh
- - Role checks for admin, creator, and affiliate routes
- - Workspace permissions for fleet actions
Database Isolation
Supabase RLS and explicit direct-client deny policies protect server-owned tables.
- - Profiles and platform settings hardened
- - Fleet/operator tables deny direct anon/authenticated access
- - Server services keep reward truth
Request Hardening
The app has security headers, validation, request guards, and rate-limit helpers where routes opt in.
- - CSP, HSTS, frame, content-type, and referrer headers
- - Zod validation on API input
- - Rate-limit and query guard utilities
Audit Evidence
Important admin and role actions write audit records, and quality/security gates produce reports.
- - Admin audit-log routes and service
- - Role-switch audit records
- - Security scans and deploy safety checks
Payment Boundary
Billing uses hosted provider flows; reward settlement proof stays owner-paid and outside platform funding.
- - Razorpay platform billing
- - Stripe creator catalog connection
- - Manual, PayPal, and UPI settlement proof records
Fleet Intake Verification
Hosted fleet candidate intake uses Authkey-backed OTP before PII submission.
- - OTP send and verify routes
- - Private OTP challenge table
- - Candidate consent and intake service path
Planned or Conditional Controls
External Developer APIRelevant later
Needs versioned external contracts, scoped keys or service accounts, quotas, audit trails, replay rules, and a sandbox story.
MFA / Admin Step-UpUseful next
Needs Supabase MFA or another central provider path, enrollment/recovery UI, and admin enforcement policy.
Formal Data Protection ProgramPartly started
Consent, exports, and retention foundations exist, but formal GDPR/DPDP-style readiness needs a data map, request workflow, and evidence.
SOC 2 Type IINot a code toggle
Relevant for enterprise sales later. It needs policies, control owners, evidence collection, vendor review, and an auditor.
PCI DSS CertificationMostly not relevant today
Hosted Stripe/Razorpay flows mean ReferCommander should avoid card data. PCI scope changes only if the app starts handling cardholder data directly.
Incident Response AutomationNot claimed yet
Logs and deploy gates exist, but automated incident response needs runbooks, alert routing, owners, and tested escalation drills.
What We Do Not Claim Yet
Claims held back until evidence exists
- SOC 2 Type II certification
- PCI DSS certification
- MFA enforced for all accounts
- 24/7 managed threat monitoring
- Automated incident response
- Specific AES-256 backup or storage guarantees beyond provider-managed encryption
Responsible Reporting
Report a vulnerability
If you find a security issue, send it through the contact page with steps to reproduce, affected route, expected impact, and safe evidence. Do not include secrets or unrelated customer data.
Review cadence
Security copy should be refreshed after material auth, RLS, API, payment, compliance, or vendor changes. Claims stay tied to code evidence and operational proof.
Security First, Without Overclaiming
The current app is on a good security path for an MVP plus Fleet V1, but formal certifications and public developer access should wait until the matching product and evidence are ready.