Security
We practice what we publish. Here is how the platform is protected.
Authentication
Passwordless Google OAuth via Supabase Auth. We never see or store your Google password, and sessions are refreshed server-side with HTTP-only handling.
Database authorization
Access is enforced by Supabase row-level security, not just hidden UI. Users can only create, edit, or delete their own content; admin actions require the admin role checked inside the database.
Transport & platform
HTTPS everywhere (Vercel + Render + Supabase). Secrets live in environment variables, never in the repository.
Report a vulnerability
Found a security issue in this site? Please do not disclose it publicly. Email hackerscolonynew@gmail.com with details and steps to reproduce — we will acknowledge within 48 hours and keep you credited if you wish.