How We Protect Your Data
You trust us with your business numbers. Here is exactly how we keep them safe.
Your Data in Transit
Every connection between your browser and KnowYourNut is encrypted with HTTPS. No exceptions. Whether you are logging in, running a calculator, or generating a business plan, your data travels through the same encryption standard used by banks and government agencies. Nobody sitting between you and our servers can read what you send.
Your Data at Rest
Once your data reaches our servers, it stays encrypted. We use Supabase for our database, and all data stored there is encrypted at rest using AES-256 encryption. Your financial numbers, business profile, and calculator results are protected even when they are just sitting in storage.
Backups and Redundancy
Your data is written to multiple disks instantly and backed up on a regular schedule. Supabase stores backups across multiple locations, so a single hardware failure does not put your information at risk. If a server goes down, your data is already somewhere else.
SOC 2 Type II Compliance
Our database provider, Supabase, has completed a SOC 2 Type II audit. This is not a self-assessment or a checkbox exercise. It means an independent auditor reviewed their security controls over an extended period and verified they actually work. This is the standard that enterprise companies require before trusting a provider with sensitive data.
Password Security
Your password is hashed before it is stored. That means we cannot see it. Our support team cannot see it. Nobody can reverse it. If you forget your password, you reset it. There is no other way, and that is by design.
Payment Security
We do not touch your credit card number. All payment processing goes through Lemon Squeezy, a PCI DSS compliant payment provider. Your card details are encrypted and handled entirely by their system. We never store, process, or have access to your full card information.
We Do Not Sell Your Data
Your financial data belongs to you. We do not sell it to advertisers, data brokers, or anyone else. We do not share it with third parties for marketing purposes. The only companies that see your data are the ones required to run the service (our database, our hosting, and our payment processor), and each of those has their own security obligations.
Row-Level Security
Every database query runs through row-level security policies. This means your account can only access your own data. Even if there were a bug in our application code, the database itself enforces the boundary. Your numbers stay yours.
Vulnerability Reporting
If you find a security issue, we want to hear about it. Contact us at security@knowyournut.com. We take every report seriously and will respond as quickly as we can.
Have questions about how we handle your data? Read our Privacy Policy or reach out at support@knowyournut.com.