LEGAL
Security
Last updated: October 9, 2026
We take the security of BetaPick and your account seriously. This page explains our general approach and how to report a vulnerability.
Our approach
Authentication is handled by Supabase, and account data is stored using our hosting and database infrastructure with access controls in place. Payments are processed by Stripe; BetaPick does not store your card details directly.
Reporting a vulnerability
If you believe you've found a security vulnerability in BetaPick, please tell us through the Contact page using the Technical issue topic, with enough detail to reproduce the issue. We ask that you give us a reasonable opportunity to investigate and fix an issue before sharing it publicly.
Please act in good faith: do not access, modify, or delete data that isn't yours, do not disrupt the service for other users, and avoid automated scans that could degrade performance for others.
What to expect from us
We will acknowledge good-faith reports made in line with the guidance above and will not pursue legal action against researchers who follow these guidelines. BetaPick does not currently operate a paid bug bounty program.