Back to home

Security Policy

Last updated 2 August 2026

How we protect the platform, and how to report an issue.

Password security

Passwords are hashed and never stored in plain text. Use a unique, strong password; enable social sign-in where possible. Never share credentials.

Encryption

All traffic is encrypted in transit with TLS. Data at rest is encrypted by our infrastructure provider. Confidential fields are additionally gated by row-level security policies.

Backups

The database is backed up on a rolling schedule with point-in-time recovery available at the infrastructure layer.

Responsible disclosure

Report vulnerabilities to capitalynx.in@gmail.com with the subject "Security disclosure". Please do not publicly disclose before we respond, do not access other users' data, and do not run destructive tests. We acknowledge within 3 business days.