Security is part of how SUBSURE monitors subscription businesses. We use access controls and technical safeguards. We do not claim an independent security certification.
Current safeguards
- OAuth access and refresh tokens are encrypted with AES-GCM before storage.
- Billing connections use read-only monitoring permissions. SUBSURE cannot charge, refund or cancel a merchant’s customers through those connections.
- Account and organisation checks restrict access to merchant data. Contract PDFs are held in a private storage bucket and limited to PDF files up to 10 MB.
- Pages and service endpoints use HTTPS. Application secrets are held in protected server-side configuration.
- Monitoring results and changes are recorded in evidence and activity records for account holders to review.
Limitations
We improve SUBSURE continuously, but no online service can be guaranteed completely secure or continuously available. We do not claim ISO 27001 or SOC 2 certification.
Report an issue
If you believe you have found a vulnerability or account security issue, email support@subsure.io with the affected page, steps to reproduce and relevant evidence. Do not include real customer personal data. We will acknowledge and investigate reports as promptly as possible.
Company details
Valico Services Ltd trading as SUBSURE · Company no. 14313622
167–169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom
