Authentication
Supabase Auth handles all authentication. Magic link and Google OAuth supported. Password auth not offered — magic links are more secure by default.
Vendors and subprocessors
See our subprocessors page for a full list of vendors that process user data on our behalf, including Anthropic (for tutoring), Stripe (billing), and Vercel/Supabase (infrastructure).
Incident response
Any security incident affecting user data is disclosed to affected users within 72 hours, along with the remediation taken. Report suspected issues to security@brainback.app. PGP available on request.
Compliance
Brainback is not currently SOC 2 or HIPAA certified. We are targeting SOC 2 Type I by the end of the coming fiscal year, driven by our institutional pilot pipeline.