Trust

Security and privacy by design

The system avoids browser-side secrets, keeps service-role keys server-only, hashes extension sessions, and keeps outreach manual.

Security posture

Supabase authentication, server-side admin access, row-level security, hashed extension sessions, and explicit user controls protect the product surface.

Responsible automation boundary

The extension can scan visible content and draft text, but it does not auto-send messages or bypass platform controls.

Security posture

Supabase authentication, server-side admin access, row-level security, hashed extension sessions, and explicit user controls protect the product surface.

No service-role key in browser
Hashed extension sessions
Admin-only routes
Manual outreach requirement

Responsible automation boundary

The extension can scan visible content and draft text, but it does not auto-send messages or bypass platform controls.

No DM blasting
No stealth behavior
No rate-limit evasion
No automatic comments
Next step

Set up your workspace and scan your first supported community.

Read setup guide