Security Policy

Last updated: August 19, 2026

Roadworthy is engineered from the ground up to protect user data, secure network transactions, and ensure robust database isolation.

Client-Side Architecture

All statistical calculations, health rating scoring algorithms, mileage discrepancy analyses, and interactive map filter states are executed locally inside your browser memory.

Row Level Security (RLS)

Every database table (including user profiles, saved garage vehicles, and push subscriptions) enforces strict Row Level Security (RLS). Database queries execute under authenticated user subqueries, ensuring users can only read or modify their own data.

Encrypted Transport (TLS / SSL)

All network queries to official UK Government data providers, Supabase REST endpoints, and Edge Functions strictly enforce TLS 1.3 encryption in transit.

Vulnerability Disclosure

If you discover a potential security vulnerability within the Roadworthy Portal or API integrations, please disclose it responsibly by emailing [email protected]. Reports are acknowledged and investigated in confidence. Our security.txt file publishes the same contact information in the machine-readable format described by RFC 9116.