Security Policy

Last updated: August 2026

Where the data lives

On Supabase, Railway, and Cloudflare infrastructure, operated in the United States. Everything travels encrypted (TLS) and is stored encrypted at rest. Large files go to object storage separate from the database.

Separation by account

Each lab sees only its own data, and that rule lives in the database, not on screen: every query goes through row-level access policies. Even if someone tampered with the application, the database would not hand them another account's data.

Access

Authentication is handled by Supabase. Passwords are never stored in the clear and sessions expire. Credentials are personal: the record of who did what depends on each person using their own.

Backups

The database is backed up automatically every day through our infrastructure provider. Even so, nothing replaces the lab exporting its critical information regularly, and the application allows that at any time.

Who on the team has access

Access to production is limited to the minimum needed to operate and support the service. No one on the team looks at your cases out of curiosity: we access them when there is a problem to solve and you asked, or when running the service requires it.

If something goes wrong

If we confirm a breach that compromises data, we notify the administrator of each affected account within the following 72 hours, as written in the privacy policy and in the DPA.

Reporting a vulnerability

If you find a security problem, write to hola@zircca.com. We treat it as a priority and take no action against anyone who reports in good faith.

Terms · Privacy · Cookies · Legal notice · Security · DPA (PDF) · Sign in

Language