Trust
Security at RewardSpring
RewardSpring handles your Stripe connection and your partners' and customers' referral data, so security is built into how the product works. Here is a plain-language overview of our practices. These describe how the product actually operates today; formal certifications such as SOC 2 are on our roadmap rather than in place.
Last updated July 16, 2026
Encryption
- All traffic is encrypted in transit using TLS (HTTPS everywhere)
- Data is encrypted at rest in our managed database and storage
- Sensitive payout details are encrypted where stored
- SSL certificates for custom domains are managed automatically via Cloudflare
Authentication and access
- Passkeys and two-factor authentication are supported; passkeys are required for platform admins
- Secure, HttpOnly cookies and managed session lifetimes for authenticated sessions
- CSRF protection for cookie-authenticated APIs
- Rate limiting on login, OTP, magic link, password reset, and passkey endpoints
- Least-privilege access controls internally, with email verification required
Tenant isolation
- Tenant isolation is enforced across all data so one account cannot access another’s
- Row-level security policies scope data access to the owning account
- One account cannot claim or route another account’s custom domain
- Reward and payout state changes are audited
Stripe and secrets handling
- We connect via Stripe OAuth (Stripe Connect) — we never store your Stripe secret keys
- We never ask customers to paste secret keys
- Stripe secrets are never exposed to the browser
- Stripe webhook signatures are verified and raw events are processed idempotently
- Connected account IDs are stored securely and sensitive admin actions are logged
Infrastructure and subprocessors
- Hosting and managed Postgres run on Supabase
- CDN, custom-domain routing, and SSL run on Cloudflare
- Transactional email is sent via Amazon SES
- Subprocessors are vetted and bound by data-protection obligations
- A current subprocessor list is available on request
Data protection
- We avoid storing unnecessary bank or payment details
- IP and user agent are hashed for fraud signals where possible
- Data is retained only as long as needed to provide the Service
- Consent-gated, privacy-friendly analytics — no advertising trackers
Vulnerability management and disclosure
- Dependencies and infrastructure are kept up to date and patched
- We welcome responsible disclosure of security issues
- Report vulnerabilities to hello@getrewardspring.com
- We investigate reports promptly and do not pursue good-faith researchers
Backups, availability, and incident response
- Automated, regularly tested database backups
- Managed, resilient infrastructure for availability
- A defined incident-response process
- Breach notification to affected customers and regulators as required by law
Incident response and breach notification
We maintain an incident-response process to detect, investigate, and contain security events. In the event of a personal-data breach, we will notify affected customers without undue delay and, where required by law, notify regulators and affected individuals. When we process data on your behalf, we will notify you so you can meet your own obligations.
Your responsibilities
Security is a shared responsibility. Please protect your login credentials and passkeys, use strong authentication, manage who has access to your account, keep your own systems secure, and only collect and share program data you are permitted to. Configure your programs and Stripe connection in line with applicable law and Stripe's terms.