← Back to Tightly

Security Policy

Last updated: 19 May 2026

Reporting a Vulnerability

Do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Please send a responsible-disclosure report by email to:

security@tightly.nl

Include as much detail as possible:

We aim to acknowledge reports within 72 hours and will keep you updated on the remediation timeline.

Data Storage & Liability Disclaimer

Tightly stores all user data — journal entries, photos, chapters, books, preferences, and feedback — in Supabase, a managed Postgres + Object Storage platform running on AWS infrastructure.

What this means for users

No warranty or liability for stored data

The operator of tightly.nl (Magnus Jerono) provides this service on an "as is" basis. To the maximum extent permitted by applicable law:

Technical Security Controls

ControlImplementation
Row-level securityEvery Supabase table is locked to auth.uid(); storage bucket paths are user-scoped
JWT verificationAll /api/* endpoints verify Supabase JWTs server-side via the service-role key
TransportHSTS (2 yr, preload), CSP, X-Frame-Options: DENY, nosniff
AI rate limitsPer-user request caps + global monthly USD spend guard
Dependency scanningDependabot, CodeQL, and npm audit in CI
Error monitoringOptional Sentry — no session replay, no PII, scrubbed request bodies
Secret scanningGitHub Advanced Security secret scanning enabled

Supported Versions

Only the latest production deployment at tightly.nl is actively maintained. There are no separately versioned releases.

Privacy Policy  ·  Terms of Service  ·  hello@tightly.nl