Security
Version 2026-10-01. Operated by Teb, an online service operated from Israel by its individual owner; paid purchases are sold and invoiced by Freemius, Inc. as merchant of record.
Architecture
- Stateless serverless application on Vercel (EU region), PostgreSQL on Supabase in Frankfurt, authentication by WorkOS AuthKit (OAuth 2.1 with PKCE), payments by Freemius. Teb never stores card data.
- Open source: the full code is public at github.com/Avishaidev/Teb and can be audited.
Data protection
- TLS 1.2+ for all traffic; HSTS with preload; strict Content Security Policy with per-request nonces.
- Database encrypted at rest by the provider. Full transcripts are additionally encrypted with AES-256-GCM using a key stored only in the application environment, never in the database.
- Row-level isolation: every query is scoped to the authenticated user; database row-level security is enabled with no public policies; only the application’s service role can read data.
- Web share links carry a 128-bit random secret; only its hash is stored, and it is compared in constant time. Short Handoff codes alone grant no access.
- Users can disconnect any AI tool from the dashboard; the server refuses that tool on its next request.
- Rate limiting per user and per IP; CSRF protection on all state-changing actions.
Operations
- All changes go through code review and automated tests before deployment. Dependencies are monitored for vulnerabilities and updated weekly.
- Production access is limited to the operator with multi-factor authentication. Secrets live only in the hosting provider’s encrypted configuration.
- Automated daily deletion of expired Handoffs and transcripts. Usage logs are kept 90 days.
- Backups are encrypted and retained by the database provider for 7 days.
Incident response
If we detect a breach affecting personal data we contain it, assess impact, notify supervisory authorities within 72 hours where required, notify affected users without undue delay, and publish a post-incident summary.
Reporting a vulnerability
Email support@tebhq.com (see also /.well-known/security.txt). Please give us a reasonable time to fix before disclosure, avoid accessing other users’ data, and do not run denial-of-service tests. We do not take legal action against researchers who follow these rules. We credit reporters on request; there is no paid bounty program at this time.