Trust
Security
How we protect your workspaces, context kits and prompt packs.
Data isolation
Every table holding your content is protected by Postgres row-level security. Database rules, not just the app, only let workspace members read a workspace's packs and kits, and only editors and admins can change them.
Authentication
- Sign-in is handled by Supabase Auth, with email and password or Google.
- Sessions use secure, HTTP-only cookies and are refreshed on the server.
- Team invites are single-use, expire after 14 days, and only work for the invited email address.
Infrastructure
- Hosted on Vercel and Supabase. All traffic uses HTTPS.
- Server-only keys are kept in environment variables and never sent to the browser.
- The free tools run entirely in your browser.
AI processing
Prompt packs are generated by our template engine on our servers and in your browser. Content is sent to an AI provider only when you explicitly click “Refine with AI”.
Reporting a vulnerability
Email hello@onemarketc.com with details and steps to reproduce. Please give us reasonable time to fix the issue before disclosing it.