Server-side API keys
AI provider credentials are stored in server-side environment configuration and are not intentionally exposed to browser code.
Security
Marketing Commander is built with security and privacy at every layer.
AI provider credentials are stored in server-side environment configuration and are not intentionally exposed to browser code.
Web sessions use secure cookie settings and server-side verification on protected requests.
Supabase row-level security is used on protected data paths to help scope access to the authenticated user.
All data in transit is encrypted via TLS. Infrastructure runs on trusted providers: Vercel, Supabase, Stripe, Upstash.
Lumen prepares recommendations and drafts. Publishing and external actions remain behind explicit approval controls.
Sensitive credentials and service tokens are kept in server-side configuration rather than public client bundles.