HHypnixEducation Abroad

Trust center · Updated June 26, 2026

Security

Hypnix uses layered application controls, but no internet service can promise perfect security.

Implemented controls

Current controls include server-side authentication, owner-scoped Supabase RLS, private storage buckets, signed payment webhooks, server-managed entitlements, input validation, rate and quota controls, security headers, sensitive-log redaction, source-confidence checks, and operator kill switches.

Private documents use user-scoped storage paths and short-lived signed download URLs. Premium is enforced server-side rather than only in the interface.

Report a vulnerability

Send a concise report with the affected route, reproduction steps, impact, and any safe evidence. Do not access other users’ data, run destructive tests, or publicly disclose an issue before Hypnix has had a reasonable chance to investigate.

Hypnix does not currently operate a public paid bug bounty. Reports are acknowledged, triaged by severity, contained where necessary, remediated, and followed by credential rotation or user notification when appropriate.