LISTRUN/SECURITY
Security
What ListRun stores, who else processes it, and how to report a vulnerability.
REPORTING A VULNERABILITY
Email hello@thecompound.tech. Include the URL, what you did, and what you saw. There is no bounty and no NDA to sign. We will confirm receipt, and we will tell you what we changed.
The same address, with a machine readable expiry, is published at /.well-known/security.txt under RFC 9116.
ACCOUNTS
ListRun has no user accounts. There is nothing to sign in to, no password to reset and no session to steal. A run token is the only credential, it is only ever handed to whoever bought the run, and a build gate fails the deploy if an authentication route ever appears while this page still says otherwise.
WHAT IS STORED
- An email address, only if you type one into the subscribe form, and only after you confirm it by clicking a link.
- Anonymous page analytics with the IP address truncated before it is stored.
- The product details you submit for a run, because they are what gets typed into each directory's form.
- An email address on a purchase, so the receipt can be delivered.
WHO ELSE PROCESSES DATA
- Vercel, hosting and edge delivery; request logs
- Supabase, the database this product's own index is served from
- PostHog, product analytics, IP-truncated
- Resend, delivering the one email the subscribe form sends
- Stripe, payment, card details are entered on Stripe's own Checkout page and never reach this site
ALSO TRUE
- Everything on this site is generated from public sources and rendered as static pages; there is no user-generated content that another visitor can see.
- The whole estate runs on one Supabase project with row-level security on; this product's tables are its own.