If you discover a security vulnerability, please report it responsibly:
- Do NOT create a public GitHub issue
- Email: krishna@helloagent.in
- Include steps to reproduce
- We'll respond within 48 hours
- Never commit
.envfiles - Use environment variables for all secrets
- Enable Row Level Security (RLS) on all Supabase tables
- Rotate API keys regularly
- Use HTTPS for all webhooks