Skip to content

Security at voiqq

The controls and operating practices used to protect voiqq accounts and workspace data.

Security is part of voiqq's product design and operational workflow. This overview describes current safeguards without disclosing details that would weaken them or claiming a certification that has not been completed.

Identity and access

  • Supabase-backed authentication and server-verified sessions
  • MFA-protected, separately authorized Site Owner control plane
  • Workspace roles, project permissions, public-share grants, and database row-level policies
  • Short-lived signed grants and Turnstile checks for designated public experiences

Application and data safeguards

  • TLS in transit and provider-managed encryption at rest
  • Server-only service credentials and third-party API keys
  • Request-origin, content-type, payload-size, and rate-limit controls
  • Audit events for sensitive platform administration
  • Storage ownership checks and explicit account-deletion cleanup
  • Dependency, build, and focused security verification before release

Customer responsibilities

Customers should use unique authentication factors, review workspace membership, limit public links, avoid unnecessary sensitive data, validate imported content, and report suspicious access promptly.

Report a vulnerability

We welcome good-faith reports that follow the vulnerability disclosure policy. Do not access another user's data, disrupt availability, or publish an unremediated issue.

Read vulnerability disclosure policy