Trust
Security
SONARmetrics uses tenant isolation, encrypted connector secrets, signed webhooks, controlled support access, audit trails, and operational recovery controls to protect customer workspaces.
Security practices
- Separate tenant data schemas and explicit organization-scoped authorization.
- Encryption in transit and authenticated encryption of stored connector secrets.
- Supabase authentication, secure session cookies, and MFA step-up for sensitive owner and platform actions.
- HMAC or provider-signature verification for supported webhooks.
- Isolated request and background-worker processes with scoped service credentials where supported.
- Redacted operational logs, audit trails, time-limited masked support staging, backups, health checks, and release rollback controls.
Report a vulnerability
Send a confidential security report with a clear description, affected URL or component, reproduction steps, impact, and a safe proof of concept.
We target acknowledgement within three business days and an initial severity assessment within seven days. After validation, remediation targets are 48 hours for critical issues, 7 days for high, and 30 days for medium; a complex or provider-dependent issue may require a documented exception and coordinated status updates. Please allow time for investigation and a safe fix before public disclosure. A report does not create an entitlement to payment; no public bug-bounty program is currently offered.
Security contact policy
The authoritative reporting channel is security@sonarmetrics.io, also published in our security.txt. Use “URGENT” in the subject for an active account compromise, exposed credential, cross-customer data access, or ongoing destructive activity. Product support and privacy requests should use the dedicated addresses on our Contact page.
Send only the minimum evidence needed to reproduce the issue. Never email passwords, session tokens, private keys, or full customer datasets. We will arrange a safer transfer method if sensitive evidence is necessary. We record, triage, restrict access to, and retain reports only as needed for investigation, remediation, legal obligations, and security history.
Testing boundaries
Do not access or modify another customer’s data, perform denial-of-service or high-volume automated testing, send spam, use social engineering, exfiltrate secrets, damage data, or test third-party providers without their authorization. Stop immediately if personal data or credentials are encountered and include only the minimum evidence necessary in your report.
Account concerns
If you receive a password-change or account-security notification you did not initiate, reset your password immediately, revoke unfamiliar sessions or identities, and contact security@sonarmetrics.io.