Legal
EFFECTIVE: JUL 11, 2026
VERSION: 2026-07-11
First published Security statement, describing current practices, infrastructure providers, the responsible-disclosure channel, and the limits of any security assurance. This is the first published version.
This page describes how AltHarbor approaches security today. It is a plain description of current practice, not a certification or a guarantee.
AltHarbor runs on managed infrastructure providers — hosting on Vercel and database and authentication services on Supabase — each of which maintains its own security program. AltHarbor relies on those programs for physical and platform-layer security and is responsible for how the application is configured on top of them.
If you believe you have found a security vulnerability, report it to security@altharbor.io. Include the affected page or endpoint, steps to reproduce, and the potential impact as you understand it. Do not include exploit payloads targeting other users’ data.
AltHarbor asks that you allow a reasonable period for remediation before any public disclosure. There is currently no bug bounty program, but good-faith reports are appreciated and reviewed.
No method of transmission or storage is completely secure, and AltHarbor cannot guarantee absolute security. AltHarbor does not currently hold, and does not claim, a SOC 2 report or other third-party security certification. This page will be updated if that changes.
Research only—not investment advice or a recommendation. Verify against fund documents.