How we protect Studi
- Supabase row-level security on user data; billing and quota tables are server-only.
- AI, payment, and email API keys are used only on the server — never in the browser.
- Device-level AI spend caps, per-route rate limits, and account limits per device.
- Prompt-injection guards on AI routes; SSRF checks on URL extraction.
- Stripe handles card data; we store subscription metadata only.
Report a vulnerability
If you believe you have found a security issue, please email security@studi.ai. Include steps to reproduce and any relevant logs or screenshots. We aim to acknowledge reports within a few business days.
Please do not publicly disclose issues until we have had a reasonable chance to fix them.