Security summary
Your job folder stays private.
Payment
Checkout is hosted by Stripe. Rebate Handled never receives full card numbers. The intake opens only after the server verifies the paid order, exact product price, and private access credential.
Uploads
- Encrypted HTTPS transport
- Private Supabase Storage bucket with public access disabled
- ClamAV scan before a file enters private storage
- Random object keys that do not contain customer names, addresses, or original filenames
- PDF, JPEG, and PNG allowlist with extension, MIME, file signature, structure, count, and total-size checks
- 12-file, 15 MB per-file, and 60 MB combined limits
- No public object URLs
Application controls
- Raw-body Stripe webhook signature verification
- Cross-site request protection and secure cookies
- Rate limits on checkout, intake, status, and refund requests
- Restrictive browser security headers and no third-party page scripts
- Structured event logs without customer details or access credentials
- Read-only container support with temporary upload files restricted to
/tmp
Retention
Uploaded job files and intake metadata are scheduled for deletion 30 days after delivery, subject to the limited exceptions in the privacy notice.
Report a concern
Email orders@adorellc.pro with “Security” in the subject. Do not include passwords, card details, or extra customer records in the message.