Security

How we protect the platform, and how to report a problem to us.

Last updated: 25 August 2026

Encryption

All traffic to bube-order.com and to our API is served over HTTPS. Data is encrypted in transit, and stored on managed infrastructure with encryption at rest.

Authentication

Passwords are stored only as salted hashes, never in readable form. Sessions use short-lived access tokens with a separate refresh token. Sign-in with Google is available as an alternative to passwords.

Access control

Data is scoped to a workspace, and every API request is checked against your membership of that workspace. Roles limit what a member can see and change.

Integrations

Server-to-server integrations authenticate with a service token compared in constant time. Incoming webhooks are verified with an HMAC-SHA256 signature and a timestamp, so replayed or altered requests are rejected.

Backups

Databases are backed up on a managed schedule so a workspace can be restored after an incident.

Reporting a vulnerability

Email support@bube-order.com with enough detail to reproduce the issue. Please give us reasonable time to fix it before disclosing it publicly, and do not access or modify other people's data while testing.

We will acknowledge your report and keep you updated until it is resolved.

Reporting a compromised account

If you think an account has been taken over, change the password immediately and contact support@bube-order.com so we can end active sessions.