Security Policy
Last updated: August 2026
Where the data lives
On Supabase, Railway, and Cloudflare infrastructure, operated in the United States. Everything travels encrypted (TLS) and is stored encrypted at rest. Large files go to object storage separate from the database.
Separation by account
Each lab sees only its own data, and that rule lives in the database, not on screen: every query goes through row-level access policies. Even if someone tampered with the application, the database would not hand them another account's data.
Access
Authentication is handled by Supabase. Passwords are never stored in the clear and sessions expire. Credentials are personal: the record of who did what depends on each person using their own.
Backups
The database is backed up automatically every day through our infrastructure provider. Even so, nothing replaces the lab exporting its critical information regularly, and the application allows that at any time.
Who on the team has access
Access to production is limited to the minimum needed to operate and support the service. No one on the team looks at your cases out of curiosity: we access them when there is a problem to solve and you asked, or when running the service requires it.
If something goes wrong
If we confirm a breach that compromises data, we notify the administrator of each affected account within the following 72 hours, as written in the privacy policy and in the DPA.
Reporting a vulnerability
If you find a security problem, write to hola@zircca.com. We treat it as a priority and take no action against anyone who reports in good faith.