Cancel Cultr — Information Security Policy
1. Purpose & Scope
This policy defines how Cancel Cultr identifies, mitigates, and monitors information-security risks. It covers all systems that process or store user data: the mobile app, the API (Cloudflare Workers), the database (Supabase / PostgreSQL), and third-party processors (Plaid, Twilio, Anthropic).
2. Data We Handle & Classification
- Highly sensitive: Plaid access tokens; bank transaction data (minimized — see §4).
- Personal (PII): email address; optional mobile phone number; device push token and time zone.
- Operational: tracked shows, subscriptions, notification history.
- We do not collect or store: bank login credentials (Plaid never exposes them to us), full card numbers, SSNs, or health data.
3. Risk Identification
Primary risks assessed:
- Unauthorized access to Plaid access tokens or transaction data.
- Compromise of a privileged secret (service-role key, Plaid secret).
- Client-side exposure of server-only data.
- Third-party processor compromise.
- Excessive data retention increasing breach impact.
Risks are re-evaluated at each quarterly review and whenever a new data flow or processor is added.
4. Controls & Mitigation (operationalized today)
- Least-privilege data access. Row-Level Security is enabled on every database table with zero policies, so client applications cannot read any row directly. All data access goes through the API using a server-side service-role key. Plaid access tokens are therefore unreachable from any client by construction.
- Read-only banking. Only Plaid's Transactions product is used; the system has no ability to move money.
- Data minimization. Only streaming-matched transactions are persisted; the user's broader transaction feed is never stored. Financial account details are never sent to the LLM (only show name and price are used to generate notification copy).
- Encryption. All data in transit uses TLS (Cloudflare and Supabase). Data at rest is encrypted by Supabase (managed AES-256).
- Secrets management. Secrets live in the Cloudflare Workers secret store and in git-ignored local environment files; secrets are never committed to source control (verified before every push). Production runs in a Cloudflare account isolated from other projects. Secrets are rotated on any suspected exposure and on operator credential changes.
- Authentication. User sessions use Supabase-issued JWTs verified on every request; internal job endpoints use a timing-safe shared secret. Multi-factor authentication is enabled on the Plaid, Cloudflare, and Supabase accounts.
- Webhook integrity. Inbound Plaid webhooks are cryptographically verified (JWT signature) before processing; inbound Twilio webhooks are verified via HMAC signature.
- Revocation & deletion. Account deletion revokes all Plaid items (removing our access) and cascades a full deletion of the user's data. Data is retained only while an account is active.
5. Monitoring
- Application and error logs are captured via Cloudflare Workers observability.
- Scheduled jobs are idempotent and log run results.
- Dependency and configuration changes are type-checked and reviewed before deployment.
- The operator reviews logs and access routinely and investigates anomalies.
6. Incident Response
On a suspected security incident, the operator will: (1) contain — rotate affected secrets and, if bank data is implicated, revoke Plaid items; (2) assess scope and affected users; (3) notify affected users and Plaid in accordance with the Plaid Agreement and applicable law; (4) remediate the root cause and record the incident and corrective actions.
7. Third-Party / Sub-Processors
Cancel Cultr relies on the security programs of its processors and their standard data-processing terms: Plaid (bank data), Supabase (database / authentication), Twilio (SMS), and Anthropic (notification-copy generation). No user personal information is sold or shared for marketing.
8. Vulnerability Management
Dependencies are kept current; code changes are type-checked and reviewed before deployment. Formal third-party penetration testing and SOC 2 attestation are not currently in place given the stage of the business; this policy is reviewed for uplift as the business scales.
9. Scope Statement
Cancel Cultr is operated by a single individual at an early stage. This policy documents controls that are genuinely implemented and procedures the operator commits to following; it deliberately does not claim enterprise certifications (SOC 2, ISO 27001, external audits) that are not yet in place.