🔒 Security at DivDip
DivDip is operated by Backchannel Capital LLC. We take the security of your data seriously. This page summarizes the technical and operational controls we have in place to protect your account and information.
Data Protection
- Your data is stored in Supabase (SOC 2 Type 2 certified), hosted in the United States
- Row-level security enforces that users can only access their own data — even at the database layer
- All data is encrypted in transit (TLS) and at rest
- DivDip will never sell, rent, or trade your personal data to third parties
Authentication
- Sign in with an email and password, with Google, or with a one-time link sent to your email
- Passwords are hashed and stored by Supabase — DivDip never sees or stores your password
- Passwords must be at least 8 characters, and common or breached passwords are rejected
- Email sign-in links are single-use and expire after 60 minutes
- Sessions expire after inactivity
Payments
- Payments processed by Stripe (SOC 2 Type 2, PCI DSS Level 1 certified)
- No payment card data ever touches DivDip servers
- All billing is handled entirely within Stripe's secure environment
Infrastructure
- Application hosted on Vercel (SOC 2 Type 2 certified)
- Automated deployments from a private GitHub repository
- Uptime monitoring via UptimeRobot with 5-minute check intervals
- All API keys and secrets are stored as encrypted environment variables — never in code
Your Rights
- You can delete your account and all associated data at any time from Settings
- Data deletion is processed within 30 days
- For GDPR requests or data questions, contact privacy@divdip.com
Reporting a Vulnerability
If you believe you've found a security vulnerability in DivDip, please report it responsibly to security@divdip.com. We will respond within 48 hours.
Last updated: August 2026 · Operated by Backchannel Capital LLC · Alabama, USA