avocadius← Back to home

Security and Responsible Disclosure

Last updated: May 14, 2026

How we protect your data

We encrypt data in transit using TLS and at rest using provider-managed encryption. Access to production systems follows the principle of least privilege, secrets are stored in a managed vault, and we keep dependencies up to date with regular security updates.

Our infrastructure

Avocadius runs on Supabase in the EU region for database, authentication, and file storage, with edge delivery via Cloudflare and Vercel. Subprocessors are listed on our Subprocessors page.

Reporting a vulnerability

If you believe you have found a security vulnerability in Avocadius, please email security@avocadius.com with details and reproduction steps. Please do not disclose the issue publicly until we have had at least 90 days to investigate and remediate.

Bug bounty

We do not currently offer a paid bug bounty program. Researchers who report valid issues responsibly may, with their permission, be credited on this page.

Last reviewed

This page was last reviewed on May 14, 2026.

AvocadiusAvocadius

distract the divine.

Product
  • Sign up
  • Sign in
  • Why
  • How
Legal
  • Terms
  • Privacy
  • Cookies
  • AI Policy
Trust
  • Accessibility
  • Subprocessors
  • Security
  • Imprint
© 2026 Avocadius. All rights reserved.