Security

How we protect credentials, cost data, and your account.

Security is core to Api CostEye. Teams entrust us with API keys and commercial spend data. Our architecture is designed to keep both out of harm's way.

Credential protection

Provider API keys are encrypted at rest using Fernet encryption. Credentials are not exposed in application logs, API responses, or the browser after you save them.

Access control

Authentication is handled by Supabase Auth. Application routes and APIs enforce authenticated access so users only see projects and services they own.

Payments

Subscription payments are processed by Stripe. Card details are not stored on Api CostEye servers.

Report an issue

If you believe you found a vulnerability, please email costeye.solutions90@gmail.com with details and we will respond as quickly as we can.