Back to Home

Security

Last updated: June 18, 2026

How we protect Studi

  • Supabase row-level security on user data; billing and quota tables are server-only.
  • AI, payment, and email API keys are used only on the server — never in the browser.
  • Device-level AI spend caps, per-route rate limits, and account limits per device.
  • Prompt-injection guards on AI routes; SSRF checks on URL extraction.
  • Stripe handles card data; we store subscription metadata only.

Report a vulnerability

If you believe you have found a security issue, please email security@studi.ai. Include steps to reproduce and any relevant logs or screenshots. We aim to acknowledge reports within a few business days.

Please do not publicly disclose issues until we have had a reasonable chance to fix them.

Related policies