Security & Trust
How We Protect
What You File With Us.
A short, plain-language summary of how Timberlark's infrastructure, access controls, and testing practices work โ and how to reach us if you find a problem.
๐ Infrastructure & Data Protection
Timberlark runs on Supabase (Postgres) and Vercel, two infrastructure providers used by companies well beyond our size, rather than self-managed servers. All data in transit is encrypted via HTTPS/TLS. Application secrets and API keys live in the hosting platform's encrypted environment variable store, never in source code. Customer-facing API keys are stored as one-way hashes โ Timberlark itself cannot read a key back out once it's issued, only verify a match.
Encrypted at rest & in transit
Database storage and all network traffic use industry-standard encryption throughout.
Hashed credentials
API keys and equivalent secrets are stored as hashes, never in plain text.
Managed infrastructure
Hosting, patching, and network security are handled by established providers, not ad hoc.
๐ฃ Responsible Disclosure
If you believe you've found a security issue with Timberlark, we want to hear about it directly, before it goes anywhere else. We commit to acknowledging your report, investigating promptly, and keeping you updated as we work on a fix. Please give us a reasonable window to resolve an issue before any public disclosure, and avoid accessing, modifying, or exfiltrating data beyond what's needed to demonstrate the issue.
Found something? Please report it directly rather than posting it publicly โ we take every report seriously and respond personally.
jeanine.bradbury@timberlark.com →