SECURITY MODEL

Defense in
depth.

No honest security program promises “unhackable.” LoopBar reduces attack surface, isolates payment data, verifies ownership on every sensitive request, and limits the damage any single failure could cause.

Protection layers

  • HTTPS-only hosting with HSTS and restrictive browser security headers.
  • Email/password verification through Supabase Auth; LoopBar never stores passwords or password hashes.
  • HttpOnly, same-site, one-day LoopBar sessions stored as one-way hashes in the account database.
  • Server-side authorization for every account, billing, and payout operation.
  • Same-origin request enforcement for state-changing account and payment actions.
  • Signed Stripe webhooks with replay-time limits and constant-time signature comparison.
  • PayPal webhook signatures are verified with PayPal before any payout status changes, and event IDs are stored so retries cannot settle twice.
  • Non-Stripe payout destinations are encrypted with AES-256-GCM, revealed only to the server during payout submission, and secret-keyed fingerprints prevent one destination from funding duplicate reward accounts.
  • Managed campaign artwork must be PNG, JPEG, or WebP with exact 728×90, 320×50, or 160×600 dimensions and strict file-weight limits before isolated object storage accepts it.
  • Public campaign checkout, application, and creative-upload endpoints are closed and return a non-cacheable 410 response.
  • Ad-provider credentials remain server-side; browser extensions receive only validated fixed-format creative fields and LoopBar tracking links.
  • Provider impression and click callbacks use unique idempotency keys so retries cannot create duplicate events.
  • Only authenticated provider receipts or internally authorized verified funding can create withdrawable revenue. Unverified provider prices fail closed at $0.
  • Per-device and account-wide pacing, simultaneous pending-view limits, active-installation limits, expiry windows, and atomic campaign-budget charging restrict automated or duplicated traffic.
  • One account may link several browser profiles, but every installation shares the same Wallet and account-wide earning ceiling.
  • Rate limits for sign-up, sign-in, pairing, onboarding, ad events, and payout actions.
  • One-time ten-minute extension pairing links; raw device IDs never appear in account URLs.
  • Parameterized database queries and atomic payout locks prevent duplicate withdrawals.
  • No card, bank, password, or identity-document storage in LoopBar.

Hosting boundary

LoopBar runs as an owner-controlled Hostinger Node.js web app. The financial database and artwork storage remain server-only, Supabase isolates password authentication, Stripe isolates payment and Connect identity information, and PayPal processes PayPal and Venmo payouts. Production secrets belong in encrypted hosting environment variables and are never committed to source code or placed in browser storage.

Verification before launch

Automated dependency, route, schema, authorization, and webhook tests are required before each release. Before handling material balances, LoopBar should add an independent penetration test, a vulnerability disclosure process, alerting, backups, recovery drills, and periodic access reviews.

Current status: architecture hardened and internally tested; not yet independently audited or certified.