HCO

Security

We practice what we publish. Here is how the platform is protected.

Authentication

Passwordless Google OAuth via Supabase Auth. We never see or store your Google password, and sessions are refreshed server-side with HTTP-only handling.

Database authorization

Access is enforced by Supabase row-level security, not just hidden UI. Users can only create, edit, or delete their own content; admin actions require the admin role checked inside the database.

Transport & platform

HTTPS everywhere (Vercel + Render + Supabase). Secrets live in environment variables, never in the repository.

Report a vulnerability

Found a security issue in this site? Please do not disclose it publicly. Email hackerscolonynew@gmail.com with details and steps to reproduce — we will acknowledge within 48 hours and keep you credited if you wish.