Security
Last updated: September 26, 2026
Your stock, recipes and purchasing data are business-critical. This page summarises how we protect them. It is a summary, not a contractual commitment; the binding terms are in the Terms of Service and the Data Processing Addendum.
Hosting and data location
- The application database, authentication and file storage run on Supabase in
the European Union (Frankfurt,
eu-central-1). - The web application is served through Vercel's global network.
- Error reports are processed by Sentry in its EU data centre (Germany), without IP addresses, cookies or form contents.
- All providers are listed on the Subprocessors page.
Access control
- Every company's data is separated at database level with row-level security, so one customer can never read another customer's records.
- Roles (owner, manager, staff) limit what each team member can see and change.
- Two-factor authentication is available to every user and mandatory for our own administrative access.
- Our internal access follows least privilege.
Encryption
- All traffic is encrypted in transit with TLS.
- Data is encrypted at rest by our hosting providers.
- Passwords are never stored in plain text.
Backups and deletion
- The production database is backed up daily; backups are encrypted before they leave the database and kept for 90 days.
- When a company account is deleted, its data is archived for 180 days so it can be restored, then deleted permanently.
Reporting a vulnerability
If you believe you have found a security vulnerability, please email security@bevorax.im before disclosing it publicly, with enough detail for us to reproduce it. We will acknowledge your report, keep you informed, and not pursue good-faith research that respects our Acceptable Use Policy, avoids accessing other customers' data, and gives us reasonable time to fix the issue.

