Security

Last updated: July 22, 2026

Current posture, without marketing shorthand. load·in is local-first, protects network traffic with HTTPS, offers password-protected project files, and limits server processing to the features you choose. Optional sync and web import/export do transmit data; the details are below and in the Privacy Policy.

HTTPS/TLS Local-First Storage Protected .show Files No Card Storage

1. How We Protect Your Data

1.1 Transport Security

All data transmitted between your browser and our servers is protected using:

1.2 Data Storage Security

Your application data (stage plots, input lists, and projects):

License and payment data:

1.3 Payment Security

We use Stripe for web payment processing and Apple for in-app purchases.

2. Infrastructure Security

2.1 Hosting and Infrastructure Providers

Service Provider Role
Hosting Vercel HTTPS hosting and serverless API execution
Database Supabase (AWS) Account, entitlement, and optional sync storage
Payment Stripe Hosted web checkout and payment processing
Error Monitoring Sentry Web-app error diagnostics; not loaded in the native iOS app

2.2 Network Security

2.3 Access Control

3. Application Security

3.1 License Verification

Pro access is verified through platform purchase state or a server-issued web entitlement:

3.2 Content Security Policy (CSP)

We use Content Security Policy and related response headers to constrain browser capabilities:

3.3 Dependency Management

4. Privacy-by-Design

4.1 Local-First Architecture

Our applications are built with privacy as the foundation:

4.2 Minimal Data Collection

We collect the absolute minimum data necessary:

See our Privacy Policy for full details.

5. Your Responsibilities

Security is a shared responsibility. Here's how you can protect your data:

5.1 Protect Your License Key

5.2 Keep Backups

5.3 Use Secure Devices

5.4 Recognize Phishing

6. Vulnerability Disclosure

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.

6.1 How to Report

Email: security@goforshow.io

Please include:

6.2 Our Commitment

6.3 What NOT to Do

When testing for vulnerabilities, please:

7. Data Breach Procedures

If we confirm a security incident involving personal data, we will:

  1. Containment: Restrict the affected service or credentials
  2. Assessment: Determine the scope, data involved, and likely impact
  3. Notification: Notify affected users and authorities when required by applicable law
  4. Remediation: Correct the underlying issue and restore service safely
  5. Review: Record what happened and improve the relevant controls

8. Privacy and Provider Responsibilities

Our Privacy Policy explains the rights available in applicable regions and how to request access, correction, or deletion. Stripe, Apple, RevenueCat, Supabase, Vercel, analytics providers, and email providers operate parts of the service under their own security and privacy programs. Their inclusion here is not a claim that go·for·show itself holds their certifications.

9. General Security Practices

10. Questions or Concerns?

If you have security questions or concerns:

Security issues: security@goforshow.io
General inquiries: goforshowio@gmail.com
Support: goforshowio@gmail.com

Operating as: go·for·show
Location: New York City, USA

Security is an ongoing process. This page describes controls we can substantiate in the current product. Report a mismatch or vulnerability to security@goforshow.io.