Security

Security and responsible disclosure

GoalPush applies tenant isolation, server-side authority, managed secrets, encrypted private data and bounded operational evidence.

Effective
30 July 2026
Version
1.0

How GoalPush protects the service

  • Firebase identity is separate from authoritative workspace membership and role checks.
  • Installation keys identify properties; secret ingestion keys are revealed once and stored hash-only.
  • Provider credentials and eligible private enrichment are encrypted with versioned server-only keys and context-bound authenticated encryption.
  • Payment fields are hosted by Stripe Elements. GoalPush does not handle card numbers or CVCs.
  • Provider requests, webhooks, retries and background work use bounded, idempotent and server-authoritative controls.
  • Logs and diagnostics exclude secrets, raw identity, URLs and complete provider payloads.

These controls reduce risk but do not make any service immune from security incidents. GoalPush does not claim a certification that has not been independently awarded.

Report a vulnerability

Send reports privately to security@goalpush.io. Include affected URLs, reproducible steps, expected impact and safe evidence. Do not access another customer’s data, disrupt service, use social engineering, run destructive tests or publish details before a reasonable remediation period.

What happens next

We aim to acknowledge critical security reports within four business hours during published support hours. This is a response target, not an SLA or guaranteed resolution time. We will validate, contain, remediate and communicate verified impact through appropriate channels.

Version history

Version 1.0 — 30 July 2026: initial controlled-launch policy.