Platform security controls
Survetify applies layered controls appropriate to a cloud business application. Current controls include:
- encrypted HTTPS/TLS transport for web, API and mobile connections;
- Supabase authentication with expiring sessions and server-enforced database row-level security;
- organisation, project and role-based access boundaries;
- private file delivery through authenticated API paths rather than public file URLs;
- server-side storage of service-role, AI and signing secrets;
- audit records for important user, manager and AI-assisted actions;
- mobile release signing through Apple, Google and EAS credential systems;
- dependency and release checks, including a native-only control that rejects WebView use; and
- operational review of risk, access and deletion requests.
Security controls evolve with the service. This page describes the current approach but is not a certification or guarantee that no incident can occur.
AI and project information
AI features send only the context reasonably required for the requested task to the configured AI provider. Customer project content is not intentionally used to train a public or general-purpose AI model without express written agreement. AI findings are stored with source context and require human review before professional or field reliance.
Responsible vulnerability disclosure
Email security@survetify.com with a clear description, affected URL/feature, reproduction steps and impact. Use test or fictional data wherever possible.
We will acknowledge credible reports, investigate in good faith and keep the reporter informed where practical. This is not a paid bug-bounty program and no reward is promised.
Incident response
Our response follows four practical stages: contain, assess, notify where required, and review. We preserve relevant evidence, restrict access, work with affected providers/customers and assess obligations under the Australian Notifiable Data Breaches scheme where applicable.
For an active account compromise, email security@survetify.com and ask your organisation Owner or Survey Manager to remove affected access immediately.