SuperKuba

Legal

Security

Last updated: 2026-08-29. This page describes SuperKuba's current security architecture. SuperKuba does not hold third-party security certifications (such as SOC 2 or ISO 27001) at this time.

Tenant isolation

Every business's data is scoped by business ID at the database and application layers. Team members only access the business they are currently signed into, and requests that attempt to reference another business's records are rejected rather than silently redirected.

Role-based access control

Access within a business is controlled by roles and permissions (for example, owner, admin, and staff roles) that are checked independently of your subscription plan. Plan entitlements and RBAC permissions are enforced separately, so upgrading a plan does not itself grant a role a capability it was not already permitted to use.

AI employee authority

AI employees always operate within the business context of the account that configured them — an AI employee cannot read or act on another business's data. Sensitive customer-communication actions requested by an AI employee are queued for a human with approval authority to review before anything is sent to a real customer.

Webhook and provider security

Inbound webhooks from connected providers (including WhatsApp/Meta, Stripe, and Paystack) are verified using each provider's signature scheme before their content is trusted or processed. Connected-channel credentials (such as WhatsApp access tokens) are encrypted before storage.

Payments

Subscription payments are processed by Stripe or Paystack through their hosted checkout pages. SuperKuba does not receive, process, or store raw card numbers, CVV codes, or full payment credentials.

Auditability

Sensitive actions — including team role changes, business profile updates, billing changes, and approved communication actions — are recorded in an internal audit log tied to the business and, where applicable, the user who performed the action.

Reporting a security issue

If you believe you have found a security vulnerability in SuperKuba, please contact us through the Contact Sales form and describe the issue in detail. We will acknowledge reports and follow up as we investigate.