Security
eFinder separates the public marketing site from an authenticated workspace. Provider and database credentials remain in server-side functions.
Data isolation
Application tables use Supabase row-level security. Privileged database operations verify the authenticated user and workspace ownership before changing searches, credits, Contacts, folders, or grids.
Research safety
Provider, AI, CSV, and professional-contact payloads are treated as untrusted text. Inputs and structured outputs are validated, source URLs are constrained to public HTTP or HTTPS links, and research is never rendered as HTML.
Payments
Card data is entered on Stripe's hosted checkout page and never reaches our servers.
Reporting
Report a suspected security issue to security@efinder.io. This page describes implemented controls and does not claim an external certification.