Bidmint
Security
Bidmint keeps private business work behind authenticated ownership boundaries and keeps public quote access limited to unpredictable quote tokens.
Product boundaries
Supabase Auth, server-side authorization, and database row-level security protect businesses, customers, quotes, payment details, and events. Public quote DTOs intentionally omit internal IDs, account data, private metadata, and analytics.
Secrets and payments
Service-role keys and payment-provider credentials remain server-side. Payment collection is hosted/tokenized by the configured provider; Bidmint does not ask for raw card numbers or CVV data.
Reporting
For a suspected account, public quote, API, or secret-handling issue, use the private support/security channel provided with your account. Do not include credentials, access tokens, private quote content, or payment data in a report.