Security
A plain description of how CommonTape protects the data it holds today. It will be updated as the booking service goes live and handles more.
Hosting
The site runs on Vercel and is served over HTTPS everywhere.
Database access
Data is stored in Supabase Postgres. Row-level security is enabled on every table, including the tables that hold agent keys and customer details, with no browser-side access policies, so the public key in your browser can’t read or write anything. Only our server, using a secret service key, can read or write data. That key is never sent to a browser.
Agent access
AI agents connect with individual API keys. We store only a one-way hash of each key, never the key itself, and a key can be revoked at any time. Each key has request-rate and open-hold limits, and an agent can only see and act on its own bookings; another agent’s booking is indistinguishable from one that doesn’t exist. Approval and merchant-side actions are never available through the agent API.
Errors returned to agents use a fixed set of codes; internal details are never exposed. Customer contact details are stored only for the job, are visible only to CommonTape’s server and the business doing the job, and are deleted automatically if the job doesn’t happen.
Secrets
API keys and other secrets live in encrypted environment variables on our hosting platform and in local development files that are excluded from version control. They are never committed to our code.
Abuse protection
The waitlist form includes a hidden field that filters out automated submissions, and inputs are validated on our server.
Data minimization
We collect only what the waitlist needs (see our Privacy Policy). We run no advertising trackers or analytics pixels.
What we don’t claim
CommonTape does not currently hold SOC 2, ISO 27001 or similar certifications, and has not undergone a formal third-party audit.
Report a vulnerability
Found a security issue? Email hello@commontape.com with “Security” in the subject line. We’ll read it promptly.