Security
Effective: August 4, 2026
Version: security-2026-08-04
Last reviewed: August 4, 2026
Verified security and operational safeguards used by ResearchCast.
1. Implemented Controls
- Supabase authentication and row-level security for user data separation.
- Private storage for uploaded papers and upload-derived generated audio.
- CSRF/origin checks on mutating API requests and abuse/rate-limit controls on sensitive flows.
- Cloudflare Turnstile on signup where enabled.
- Distributed rate limits fail closed on protected production routes when the configured Redis/KV store is unavailable.
- Paddle and Resend webhook signatures are verified before events are processed, and provider event IDs are stored idempotently.
- Sentry receives scrubbed error events without default PII, request bodies, headers, cookies, user data, breadcrumbs, logs, replay, or performance traces.
- Retention cleanup for logs, tokens, email events, reports, generation traces, and expired uploads.
- Least-privilege service-role use in server-only code paths.
2. Generation and Source Controls
- User uploads are processed for the requesting user and deleted according to retention/deletion rules.
- arXiv access uses official metadata and PDF endpoints where available.
- Remote third-party PDFs are blocked unless explicitly allowlisted or supported by source-compliance checks.
- Generated output is labeled as AI-generated and should be verified against original sources.
3. Incident and Vulnerability Contact
Report security concerns to support@research-cast.com. Include the affected URL or feature, impact, reproducible steps, and any non-sensitive supporting material. Do not access, retain, or modify data that is not yours, disrupt the service, or publicly disclose an unresolved issue.
We will triage reports, preserve relevant evidence, and coordinate follow-up through the reporting address. This page and `/.well-known/security.txt` are the canonical public vulnerability-reporting contacts. ResearchCast does not promise a bounty or authorize activity that would otherwise be unlawful.
4. Assurance Boundaries
ResearchCast has not claimed an ISO, SOC, BSI, or comparable third-party security certification on this page. Provider certifications do not certify ResearchCast itself. Controls and provider configurations can change; the version and last-reviewed date identify the review represented here.
Security is risk management, not a guarantee. Please use a unique password, protect the connected email or OAuth account, review public-sharing choices, and do not upload data that the Service prohibits or that requires safeguards not expressly agreed with ResearchCast.