Legal

Security & Compliance

Last updated:

September 8, 2026

Our approach

Security isn't a separate initiative bolted onto Redirect Supply — it's built into how the product works by default. This page describes the actual practices we follow to protect your data and your redirects.

Encryption everywhere

Every redirect delivered through Redirect Supply is served over HTTPS automatically, with certificates issued and renewed without any manual step. Data in transit between your visitors, our infrastructure, and your destination is encrypted by default. Data at rest in our database is encrypted using our infrastructure provider's standard encryption.

No passwords to steal

Redirect Supply doesn't use passwords. You sign in through a one-time magic link sent to your email, or through Google Sign-In. This removes an entire category of risk that affects most SaaS products — there's no password database that could be breached or reused from another site, and no risk of credential-stuffing attacks against your account.

Infrastructure

We build on established infrastructure providers rather than running our own servers: Cloudflare for DNS, redirect delivery, and network-level protection; Vercel for hosting our application; and Supabase for our database and authentication layer. Each of these providers maintains its own security practices and certifications at a scale we couldn’t replicate independently.

We build on established infrastructure providers rather than running our own servers: Cloudflare for DNS, redirect delivery, and network-level protection; Vercel for hosting our application; and Supabase for our database and authentication layer. Each of these providers maintains its own security practices and certifications at a scale we couldn't replicate independently.

Data residency

Your account and application data is stored in Ireland, within the European Union, through our database provider Supabase.

Vetted subprocessors

Every third-party service we rely on to deliver Redirect Supply is bound by a data processing agreement and used only for the specific purpose we’ve disclosed. Our current subprocessors, including their location and role, are listed on our Subprocessors page.

Every third-party service we rely on to deliver Redirect Supply is bound by a data processing agreement and used only for the specific purpose we've disclosed. Our current subprocessors, including their location and role, are listed on our Subprocessors page.

Responsible disclosure

If you've found a security vulnerability in Redirect Supply, we want to know about it before anyone else does. Email daniel@redirect.supply with details, and we'll respond as quickly as we can.

Compliance

Redirect Supply is built to align with GDPR requirements as a Czech-registered company, including the data processing terms and subprocessor transparency described above. We don't currently hold formal third-party certifications such as SOC 2 or ISO 27001 — we're a small, early-stage team and have prioritized building genuinely sound practices first. We're happy to complete security questionnaires on request as we work with more customers.