SupaBook is built on a security-first foundation. Every workspace is isolated, every request is authenticated, and every sensitive action is logged. We treat your client data like our own.
Each studio (workspace) operates inside its own logical tenant. Database-level Row Level Security (RLS) policies enforce that users in one studio can never read or write data in another, even if they discover internal IDs. There is no shared "all customers" table that requires application-side filtering.
SupaBook partners with Stripe for secure payment processing. Stripe collects and tokenizes sensitive card and ACH details, while SupaBook stores the business records needed for invoices, receipts, project history, and reconciliation.
SupaBook does not use your business content to train general-purpose AI models or authorize providers to use it for that purpose. Providers may retain data for service operation, security, abuse prevention, or legal obligations under the applicable service terms. This is not a promise of zero data retention. See the AI Features Terms.
Responsible disclosure is welcome. Report issues to security@supabook.ai. We acknowledge within one business day.
Related: Security, Privacy Policy, Terms of Service.
Canonical page: Trust Center canonical page