eFinderSecure workspace

Security

eFinder separates the public marketing site from an authenticated workspace. Provider and database credentials remain in server-side functions.

Data isolation

Application tables use Supabase row-level security. Privileged database operations verify the authenticated user and workspace ownership before changing searches, credits, Contacts, folders, or grids.

Research safety

Provider, AI, CSV, and professional-contact payloads are treated as untrusted text. Inputs and structured outputs are validated, source URLs are constrained to public HTTP or HTTPS links, and research is never rendered as HTML.

Payments

Card data is entered on Stripe's hosted checkout page and never reaches our servers.

Reporting

Report a suspected security issue to security@efinder.io. This page describes implemented controls and does not claim an external certification.