Security

This page states what actually protects your account today. It is deliberately short: ToolPackHub is a young product run by a small team, and a wall of certification logos would not say anything true.

HTTPS / TLS

Supabase Auth

RGPD : politique publiee

Accounts and Passwords

Sign-up, login, and password reset all go through Supabase Auth. Your password is hashed by Supabase before it is stored; it never reaches our own code in plain text, and no one here can read it back. If you forget it, the reset link is the only way to regain access.

Traffic between your browser and the site runs over HTTPS with TLS, from the login form to the dashboard to the API.

Where Your Data Lives

  • Application: hosted at Hostinger, running as a Node.js process behind their web server.
  • Database and authentication: Supabase (managed PostgreSQL), including the backups included in their plans.
  • Social platforms: when you connect an account, the access token issued by that platform is kept in order to publish on your behalf. Disconnecting the account removes it.

What We Do Not Claim

Earlier versions of this page mentioned SOC 2 Type II certification, ISO 27001, quarterly penetration testing, a 24/7 monitoring center, and a bug bounty program. None of that existed. It has been removed, not softened.

  • No SOC 2 or ISO 27001 audit has been carried out.
  • There is no contractual uptime commitment. We do not publish any SLA figures.
  • There is no paid bug bounty program.
  • Monitoring is not provided around the clock.

If any of this becomes true, this page will say so, with a date and the auditor's name.

Personal Data and GDPR

We collect the account data you provide us and the technical data necessary for the service to function. We do not sell it and do not share it with advertisers. The full list, along with how to obtain a copy of it or have it deleted, is set out in the privacy policy.

In the event of a breach affecting your personal data, we are required to notify the competent supervisory authority within 72 hours, and to notify you directly if the risk to you is high. This obligation applies regardless of any certification.

Reporting a Vulnerability

Write to info@omnilearn.org with enough detail for us to reproduce the issue. You will get a reply from a human. There is no reward program, so please do not expect one, but credit can be given on request once the fix has been published.

Please do not run automated scans against the production site, and do not touch other accounts' data.

ToolPackHub is published by OmniLearnConsultingCommerce LLC, 447 Broadway, 2nd Floor, Suite 3259, New York, NY 10013, United States.