Legal & trust
Data Security
A factual overview of the safeguards used to protect Konekte accounts and application data.
Last updated: July 12, 2026
Application and data access
Konekte uses Supabase authentication, server-side authorization checks, role-based interfaces, and PostgreSQL row-level security policies to restrict access. Public marketplace views expose a limited profile field set rather than private ownership or payment-setting records.
Billing and payment data
Stripe processes subscription checkout and sends signed webhook events to Konekte. Campaign payments do not pass through Konekte. Profile validation is designed to reject full bank and card account numbers in payment-preference fields.
Operational safeguards
The codebase includes audit records for elevated administrative actions, restricted administrative routes, webhook-event records, and documented reviews of elevated database functions. Safeguards reduce risk but cannot eliminate it.
Responsible reporting
Do not publicly disclose active vulnerabilities or access data beyond what is needed to demonstrate an issue. Security concerns should be sent through the support or security contact channel published in the service with reproduction details and potential impact.