Security Policy
Last updated 2 August 2026
How we protect the platform, and how to report an issue.
Password security
Passwords are hashed and never stored in plain text. Use a unique, strong password; enable social sign-in where possible. Never share credentials.
Encryption
All traffic is encrypted in transit with TLS. Data at rest is encrypted by our infrastructure provider. Confidential fields are additionally gated by row-level security policies.
Backups
The database is backed up on a rolling schedule with point-in-time recovery available at the infrastructure layer.
Responsible disclosure
Report vulnerabilities to capitalynx.in@gmail.com with the subject "Security disclosure". Please do not publicly disclose before we respond, do not access other users' data, and do not run destructive tests. We acknowledge within 3 business days.