Legal

Security

Last updated: June 10, 2026

We take the security of your business and lead data seriously. This page summarizes the practices in place today.

Encryption

Data is encrypted in transit using TLS. Data at rest is encrypted by our database and storage providers.

Tenant isolation

Every table is protected by row-level security. Access policies ensure a business owner can read and write only their own data. Public lead forms expose only the limited fields needed to submit an inquiry.

Authentication

We support password, email OTP, phone OTP, and OAuth sign-in through our authentication provider. Passwords must meet strength requirements, and sessions are managed with secure, HTTP-only cookies.

Abuse prevention

Authentication and public lead submissions are rate-limited. Optional bot protection can be enabled on public forms. Sensitive errors are not exposed to end users.

Least privilege and secrets

Application access uses scoped, per-user credentials rather than privileged keys. Administrative keys are kept server-side and out of version control.

Responsible disclosure

If you believe you have found a security vulnerability, please report it privately to support@metamorp.live before disclosing it publicly. We will acknowledge your report and work to address valid issues promptly.

Draft notice. This document is a production-ready template for Metamorp. It is not legal advice. Please have it reviewed and adapted by a qualified lawyer for your jurisdiction before relying on it.