Legal and trust

Security at SpecCore Analytics

SpecCore uses layered controls to protect accounts, private technical files, and comparison workspaces.

Last updated: August 10, 2026

Account and access controls

Authentication is provided through Supabase with email verification, password recovery, secure session cookies, CAPTCHA support, rate limiting, and role-based administrator controls. Administrative status cannot be self-assigned through public account fields.

Private data boundaries

Uploaded files are stored in private storage paths tied to the owning user or organization. Row-level security and server-side authorization restrict project, file, extracted specification, usage, and billing records.

File and processing safeguards

SpecCore accepts only supported PDF, XLSX, and CSV inputs within configured size and batch limits. File signatures, extensions, storage paths, duplicate content, processing attempts, and extraction status are validated or recorded for review.

Operational security

Security-relevant administrator actions, support overrides, processing failures, and report actions are audited. Secrets remain server-side, Stripe webhooks require signed payloads, and production responses avoid exposing internal credentials.

Responsible disclosure

Report a suspected vulnerability to team@speccoreanalytics.com with reproduction details and avoid accessing data that is not yours. We will acknowledge and assess good-faith reports.

Questions may be sent to team@speccoreanalytics.com.