Security is a first-class concern at TrustNudge. The platform is engineered around defense in depth.
Encryption
All traffic is encrypted in transit with TLS 1.2+. Data at rest is encrypted by our managed database provider.
Access control
Row-Level Security (RLS) is enforced for every customer-facing table. Admin endpoints require a server-verified admin role and never trust client-side claims.
Secrets management
API keys for third-party providers (e.g. Brevo) live only on the server and are never exposed to the browser.
Email integrity
We enforce SPF, DKIM, and DMARC on sending domains, maintain suppression lists, honor bounces and complaints, and include CAN-SPAM-compliant footers on every email.
Responsible disclosure
If you believe you’ve found a vulnerability, email security@trustnudge.io. We appreciate your help.
Questions? Contact support@trustnudge.io or visit our homepage.