Security at Pasage

Practical safeguards, clear account boundaries and a way to report problems.

Use our official domain

Pasage's production website is https://pasage.app. It uses HTTPS. Check the address before signing in or sharing information.

Accounts and private work

Authentication is provided by Supabase. Protected operations check your account and access rights on the server. Private account pages are excluded from search indexing. A shared guest result link can be viewed by someone who has that link.

Payments and browser safeguards

Payments use Paystack or Stripe. Server-side checks verify payment notifications before granting access. Browser headers restrict executable content sources, prevent framing by other sites and limit device features. The microphone is requested when you start a Queen call.

Report vulnerabilities privately

Use our security reporting instructions. Include a URL and safe reproduction steps. Do not access other accounts, disrupt service, or include secrets. We do not publish a guaranteed response time or paid bounty programme.

Scope

These practices are not a certification or a guarantee that no vulnerability exists. We do not claim ISO certification, SOC 2 certification or an independent penetration test.