/ Security

Security
isn't a tab.
It's the layer.

Trendslop exists because vibe-coded apps ship insecure. Our own product is held to the same standard we audit our customers' apps against โ€” and the same standard their customers deserve.

๐Ÿ”

Zero standing access

We never store your AWS root keys, your Stripe secret keys, or your Supabase service-role keys. We use scoped, short-lived IAM roles and OAuth tokens โ€” refreshed per session.

๐Ÿ›ก

Least-privilege IAM

Our deploy role can only touch the S3 bucket, Lambda functions and SES identities you explicitly authorise. CloudFormation diff shown before every deploy. Nothing else gets created.

๐Ÿ“‹

Encrypted at rest & transit

AES-256 at rest. TLS 1.3 everywhere. Customer data lives in segregated tenant schemas on Supabase with row-level security policies enforced at the database layer.

๐Ÿงพ

Full audit log

Every Trendslop action โ€” patch, deploy, key rotation โ€” is logged immutably. Team and Enterprise plans get a real-time audit export for SOC 2 / ISO 27001 evidence.

๐Ÿšซ

No training on your code

Your code, your prompts, your dependency graphs โ€” none of it is ever used to train any model, ours or anyone else's. Period.

๐Ÿ’ฃ

Bug bounty

Rewards are scaled to severity and impact. See our disclosure programme for scope and how we triage.

Compliance roadmap

SOC 2Type II โ€” audit in progress
GDPREU + UK compliant
HIPAABAA available on Team plan
ISO 27001Targeting Q3 2026

What we actually check on your app

When you run a Ship audit, Trendslop checks the things every vibe-coded app fails on. The same controls our infrastructure obeys.

Responsible disclosure

Found a bug? Email security@trendslop.ai with full details. We aim to respond within 24 hours and reward valid reports based on severity and impact. Please don't open public issues.