Security

Security at Recurrio

Last reviewed: May 6, 2026

🔐
AES-256
All data encrypted at rest with industry-standard 256-bit AES encryption.
🛡
Row-Level Security
Database policies enforce users can only access their own data. No exceptions.
🔑
bcrypt Passwords
Passwords are hashed with bcrypt before storage. Even we cannot see your password.
🚫
No Bank Credentials
Recurrio never asks for banking usernames, passwords, or card numbers.
📡
TLS 1.3
All data in transit is protected with TLS 1.3 encryption on every connection.
💾
Daily Backups
Automated daily backups with point-in-time recovery on Supabase infrastructure.

Encryption & Infrastructure

Data at Rest
AES-256-GCM
Storage layer encryption
Data in Transit
TLS 1.3
Enforced on all connections
Password Hashing
bcrypt (cost 12)
Never reversible
Authentication
JWT + Refresh Tokens
Short-lived access tokens
Database
PostgreSQL (Supabase)
Row-level security
AI Proxy
Cloudflare Workers
API keys never exposed

System Status

All systems operational

Web Application
Operational
Authentication
Operational
Database
Operational
AI Assistant
Operational
PDF Generation
Operational

What We Never Do

Responsible Disclosure

Your Security Checklist