Legal
Security
Last updated: 2026-08-29. This page describes SuperKuba's current security architecture. SuperKuba does not hold third-party security certifications (such as SOC 2 or ISO 27001) at this time.
Tenant isolation
Every business's data is scoped by business ID at the database and application layers. Team members only access the business they are currently signed into, and requests that attempt to reference another business's records are rejected rather than silently redirected.
Role-based access control
Access within a business is controlled by roles and permissions (for example, owner, admin, and staff roles) that are checked independently of your subscription plan. Plan entitlements and RBAC permissions are enforced separately, so upgrading a plan does not itself grant a role a capability it was not already permitted to use.
AI employee authority
AI employees always operate within the business context of the account that configured them — an AI employee cannot read or act on another business's data. Sensitive customer-communication actions requested by an AI employee are queued for a human with approval authority to review before anything is sent to a real customer.
Webhook and provider security
Inbound webhooks from connected providers (including WhatsApp/Meta, Stripe, and Paystack) are verified using each provider's signature scheme before their content is trusted or processed. Connected-channel credentials (such as WhatsApp access tokens) are encrypted before storage.
Payments
Subscription payments are processed by Stripe or Paystack through their hosted checkout pages. SuperKuba does not receive, process, or store raw card numbers, CVV codes, or full payment credentials.
Auditability
Sensitive actions — including team role changes, business profile updates, billing changes, and approved communication actions — are recorded in an internal audit log tied to the business and, where applicable, the user who performed the action.
Reporting a security issue
If you believe you have found a security vulnerability in SuperKuba, please contact us through the Contact Sales form and describe the issue in detail. We will acknowledge reports and follow up as we investigate.
