The marketplace is designed so sensitive homeowner contact information stays out of public pages and unpaid lead previews.
Core controls
- Passwordless partner authentication: approved users authenticate through Supabase Auth; application database service keys remain server-side.
- Row-level protection: production tables are configured with Row Level Security and are not intended to expose privileged records to anonymous browser clients.
- Server-verified lead ownership: checkout and lead-access endpoints re-check the authenticated contractor and match ownership rather than trusting client-supplied prices or contractor identifiers.
- Encrypted homeowner contact fields: sensitive lead contact values are designed to be protected with AES-256-GCM using a deployment-only key shared by the two server applications.
- Hosted payments: Stripe Checkout handles card entry and webhook signatures are verified before paid access is recorded.
- Auditability: lead offers, purchases, consent evidence, webhook events, contractor status, and privacy requests are stored as separate records.
- Security headers: HSTS, Content Security Policy, frame blocking, MIME-sniffing protection, permissions restrictions, and referrer controls are configured at the Next.js layer.
- Data minimization: builder alerts contain project preview information and a portal link, not homeowner contact details.
Partner responsibilities
Partners must protect sign-in links, company email accounts, devices, internal CRMs, and any homeowner information they export. Use multi-factor authentication wherever available, remove former employees promptly, and never share portal sessions or lead data with unrelated businesses.
Incident reporting
Report suspected unauthorized access, credential theft, data exposure, or security vulnerabilities to security@adubuilderconnect.com. Do not access information that is not yours or publicly disclose a vulnerability before we have a reasonable opportunity to investigate.
Limitations
Security is a continuous process, not a guarantee. Production safety depends on correct Vercel, Supabase, Stripe, Resend, Twilio, DNS, email, credential, backup, logging, and administrative-account configuration.