Security

This page lists the security practices that are in place today. It does not describe certifications or controls we have not implemented.

API keys

  • API keys are stored only as SHA-256 hashes. The full key is shown once when you create it; we cannot display or recover it afterwards.
  • You can revoke a key from your dashboard at any time, and revoked keys stop working immediately.

Accounts

  • Sign-in and passwords are handled by Supabase Auth. Captapi's own servers never store your password.
  • You can also sign in with Google, in which case no password is created.

Payments

Checkout and billing are handled by Paddle, our merchant of record. Card details are entered on Paddle's checkout and never reach our servers.

Encryption in transit

The website and the API (api.captapi.com) are served over HTTPS only.

Infrastructure

  • API servers run on Railway.
  • The website runs on Vercel.
  • The database and authentication run on Supabase (PostgreSQL).

The full list of companies that process data for us is on the subprocessors page.

Reliability data

Measured success rate and latency per platform, with the calculation method, are public on our status page.

Reporting a security issue

Email support@captapi.com with “Security” in the subject. Please include steps to reproduce, and give us a reasonable time to fix the issue before disclosing it publicly.