Security

How VisionDraft protects your data and infrastructure.

Infrastructure

  • Hosted on Vercel with HTTPS everywhere
  • Database and auth on Supabase with row-level security
  • API keys stored as SHA-256 hashes — never in plaintext
  • Assets and exports in isolated Supabase Storage buckets per user

MCP access

MCP tools require a valid API key and active subscription. Usage limits are enforced per plan before every action.

Report a vulnerability

Email security@visiondraft.space. We appreciate responsible disclosure.