← Back to Bidmint

Bidmint

Security

Bidmint keeps private business work behind authenticated ownership boundaries and keeps public quote access limited to unpredictable quote tokens.

Product boundaries

Supabase Auth, server-side authorization, and database row-level security protect businesses, customers, quotes, payment details, and events. Public quote DTOs intentionally omit internal IDs, account data, private metadata, and analytics.

Secrets and payments

Service-role keys and payment-provider credentials remain server-side. Payment collection is hosted/tokenized by the configured provider; Bidmint does not ask for raw card numbers or CVV data.

Reporting

For a suspected account, public quote, API, or secret-handling issue, use the private support/security channel provided with your account. Do not include credentials, access tokens, private quote content, or payment data in a report.