Security

Private feedback needs a locked door.

This is what we do today — not a certificate wall of logos we have not earned.

Transport encryption

All traffic uses HTTPS with TLS. Review text, voice files, and dashboard sessions are not sent in the clear.

Built for anonymity

Public pages do not show who left a review. We do not attach a Google or social profile to feedback.

Account access

Business dashboards require a signed-in owner. API routes check that token and only return that business’s data.

Database rules

Supabase row-level security is enabled on sensitive tables. The service role key stays on the server, never in the browser.

Payments

Cards are handled by Stripe. We do not store full card numbers on ReviewShroud servers.

GDPR

You can ask what we hold and ask us to delete it. Privacy requests go to privacy@reviewshroud.com.

Found a vulnerability? Email support@reviewshroud.com with “security” in the subject. Full legal terms live in Privacy and Terms.