Security

Creator and brand data stays separated by design.

Pitchline Creators combines server-side authorization, PostgreSQL Row Level Security, narrow public links, and provider-verified webhooks.

01

Tenant isolation

Every exposed application table uses RLS. Workspace membership and role are resolved from protected relational records, never editable profile metadata.

  • Operation-specific policies
  • Cross-workspace foreign-key constraints
  • Automated isolation tests
02

Protected sharing

Media kits, pitches, portals, reports, and file downloads use scoped, revocable, expirable access with hashed bearer tokens where recovery is unnecessary.

  • Optional passwords
  • Rate limits and anti-spam
  • Private Storage buckets
03

Integration boundaries

Provider secrets and social tokens stay server-side. PayPal webhooks are verified and idempotent; AI and observability adapters remain off when unconfigured.

  • Encrypted sensitive tokens
  • No secrets in logs
  • Bounded provider calls

Controls already verified

Migrations rebuild from an empty database, all 72 public tables have RLS, and 38 PostgreSQL assertions cover isolation and roles.

Security is part of the workflow, not a settings toggle.

Read the public privacy terms or contact the security channel for a responsible report.

Start for free