← Isiofia

Security

Last reviewed · July 29, 2026

Isiofia builds and operates software that holds real information about real people. Here is precisely how that information is handled. No badges, no certifications we do not hold, just what the systems actually do.

01Encryption

Every Isiofia property is served over HTTPS only. Data is encrypted at rest by our database provider using AES-256.

02Isolation between accounts

Access is enforced in the database with row level security, not only in the interface. A signed-in user’s request reaches their own records and nothing else, because the database itself refuses anything wider. A tampered browser cannot widen it.

03Privileged actions

Administrative operations verify the caller’s identity inside the database function that performs them. Calling the API directly is no easier than clicking the button.

04Sign-in

Google sign-in is the primary route into our products. For those accounts we never receive, store, or transmit a password.

05Credentials

Server-side keys live in the hosting platform’s secret store. They are never included in anything sent to a browser.

06Your mailbox stays yours

Where a product sends email on your behalf, it does so through your own Google or Microsoft account by OAuth. We never hold your mailbox password, and you can revoke access at any time from your provider’s account settings.

07Payments

Where a product takes payment, card details are entered on our payment processor’s own hosted page, on their domain. No Isiofia product renders a card field, and no card number reaches a form we wrote, a request we serve, or a log we keep.

08Where data lives

Our infrastructure runs on Supabase, Vercel, and Fly.io. A current list of every third party that processes data is available on request.

09Reviews

We run automated security checks against our databases and re-read our access rules on a schedule, not only after something goes wrong. Findings are recorded and fixed.

10Reporting a problem

If you believe you have found a security issue, email isiofiachiji@gmail.com or use the form below. Both reach a person, not a queue. We will confirm receipt, we will not pursue you for reporting something in good faith, and we will tell you when it is fixed.

Please do not access, modify, or exfiltrate data belonging to anyone else while investigating, and give us a reasonable window to fix a problem before publishing it.

Please do not include anyone else’s personal data in this form. Describe the problem and we will reproduce it ourselves.

11What we do not claim

We are not SOC 2 certified. We are not a HIPAA covered entity, because no Isiofia product handles health information. We hold no ISO 27001 certification and no PCI attestation. We would rather tell you that plainly than display a badge we have not earned.

12Who operates this

isiofia.org and the products listed on it are operated by Chijindu Isiofia, doing business as Isiofia, in New York.