Skip to content
Brownie Helps
Legal

Security

How we keep your work safe.

Security basics, in plain language — what we do today, and what we don’t claim.

Authentication

Sign-in is handled by Supabase Auth, supporting email/password and Google OAuth. We never see or store your Google password. Session tokens are handled by Supabase’s standard auth flow over HTTPS.

Payments

All card payments are processed by Stripe. Brownie Helps never receives or stores your full card number — Stripe does, under its own PCI-compliant infrastructure.

Channel connections

Connections to social platforms, ad accounts, ESPs, and CRMs (e.g. GoHighLevel) use that platform’s own OAuth flow. We store the access token issued to us — not your password for that platform — scoped to the minimum permissions the connection needs. You can revoke any connection at any time from the portal, which immediately stops us from using that token.

Data in transit & at rest

Traffic to and from browniehelps.com is encrypted (HTTPS/TLS). Application data lives in Supabase’s managed Postgres, which encrypts data at rest.

Access controls

Client accounts are isolated by workspace — one client cannot see another client’s data. Internal staff access to client data is limited to what’s needed to deliver and support the engagement.

What we don’t claim

We’re a small, growing team. We do not currently hold formal third-party security certifications (e.g. SOC 2, ISO 27001), and we won’t claim ones we don’t have. If that changes, this page will say so, and we’ll be able to show you the audit.

Reporting an issue

If you believe you’ve found a security issue, email derek@browniehelps.com with details. We take reports seriously and will respond promptly.

Last updated: July 6, 2026 · Questions? Contact us.