Security
How we protect Everly and your events
Infrastructure
Data is stored in Google Firebase (Firestore) with owner/member access rules. Public invitation data is served via server-side Admin SDK only — clients cannot read other events or invite tokens.
Authentication
Email/password and Google OAuth via Firebase Auth. API routes verify ID tokens on every protected request.
Responsible disclosure
If you discover a security issue, please report it responsibly to support@everlymagic.com with the subject line "Security report". Include steps to reproduce and impact. We aim to respond within 72 hours.