Security Specifications
Last updated: June 29, 2026
1. Secure Authentication & Session Safety
Your credentials are never stored directly on our servers.
- AuthJS Standard: We utilize AuthJS / NextAuth for federated login flows. Your passwords never enter our databases.
- OAuth Handshake: We requests minimal read-only scopes. We never request permission to manage your videos, delete comments, or edit uploads.
- Tokens Encryption: Access tokens and refresh tokens received during OAuth are encrypted using cryptographic keys at rest in Supabase.
2. Network & Storage Layer Protection
All traffic inside CreatorsHub is routed over TLS 1.3 / SSL ensuring full encryption in-transit.
Our database is hosted with Supabase which uses AES-256 encryption at rest. Network requests between the Render app servers and the Supabase PostgreSQL cluster are secured using authenticated SSL connections.
3. Payments Compliance
CreatorsHub does not process or store credit card details. All billing flows are processed natively inside Paddle’s Level 1 PCI-compliant billing terminals.
4. Reporting a Security Issue
If you identify a vulnerability or security flaw within the CreatorsHub ecosystem, please report it to our security desk at kodastech@gmail.com rather than sharing it publicly. We review and resolve security logs in less than 24 hours.