No exceptions - every field, every algorithm, every limitation. No marketing here, just engineering facts.
Encrypted on sender device, decrypted on recipient device
Encrypted before upload to storage
OTP stored as SHA-256 hash. Key derived from the OTP itself
Field-level encrypted in Supabase, key in GCP
Hash + 32-byte salt in DB. Cannot be reversed
Hash stored in DB. Original token only on device
Only hash stored - raw IP is not persisted
Vercel manages env var encryption. SOC 2 Type II certified
⚠️ Vercel employees can theoretically access
Cloud Run me-west1 (Israel). Separated from Vercel
Managed by Vercel Marketplace auto-provisioning
Random UUIDs - contain no sensitive info, used for state management
Audit log and tracking - required for SOC 2 compliance
"encrypt", "scan", "fix" - without the action content itself
"79 fixes" - without detail of what they are
Public files - TLS in transit, CDN cached
All the following headers are active on every server response: