Security

Know exactly what Dunity can touch

Dunity works through a restricted Stripe key that you create and can revoke at any time. Here is every permission it asks for, what it keeps, and what it never sees.

  • $29/month, flat
  • Cancel anytime
  • Restricted Stripe key only

The eight Stripe permissions

You create a restricted key in Stripe with exactly these permissions. Dunity checks them when you connect and tells you if one is missing.

  • Webhook Endpoints · WriteSets up the webhook that tells Dunity when a payment fails, and removes it when you disconnect.
  • Invoices · WriteRetries the charge on an invoice your customer already owes.
  • Payment Intents · ReadReads why a payment failed, so the next retry can be timed to the decline reason.
  • Customers · WriteSaves the new card a customer enters as their default, so the next retry uses it.
  • Checkout Sessions · WriteOpens the secure Stripe page where a customer enters a new card.
  • Setup Intents · ReadConfirms which card was saved on that page.
  • Payment Methods · ReadReads a card’s brand, last four digits and expiry for card-expiry reminders. Never the full number.
  • Credit Notes · WriteApplies the win-back discount you choose, as a credit on the unpaid invoice.

There is no permission to create refunds, payouts or transfers. Revoking the key in Stripe cuts off Dunity’s access immediately. The Stripe setup guide walks through creating the key.

What Dunity keeps, and what it never sees

Keeps

  • Your account email and your Dunity settings
  • Your restricted Stripe key and webhook secret, encrypted
  • For each failed invoice: its ID, customer ID, amount, currency, decline reason and retry history
  • Your customers’ email addresses, and a log of the emails Dunity sent them
  • A Slack webhook address, encrypted, if you connect Slack

Never sees or keeps

  • Full card numbers or security codes. Stripe doesn’t send them to Dunity.
  • Your Stripe secret key. Dunity only accepts a restricted key.
  • Card brand, last four digits and expiry. They’re read for expiry reminders, then not stored.
  • Your password. Sign-in is handled by Clerk.

How long each of these is kept is in the privacy policy.

How it’s protected

  • Encrypted in transit

    Every connection to Dunity uses HTTPS, and browsers are told never to fall back to plain HTTP.

  • Keys encrypted at rest

    Your Stripe key and any Slack webhook address are encrypted in Supabase Vault and never sent back to your browser.

  • Only real Stripe events

    Dunity checks the signature on every webhook before acting on it, so it only responds to events that came from Stripe.

  • Signed, expiring card-update links

    The links in customer emails are signed and expire after 45 days. A link for an invoice that’s already been recovered stops working.

  • A secret stored like a password

    The payment wall’s secret is shown to you once and stored only as a hash.

  • No database access from browsers

    Only Dunity’s servers can reach the database. Nothing in your browser, or your customers’, talks to it directly.

  • Rate-limited public endpoints

    The payment wall and card-update pages limit how often they can be called.

  • Dependencies checked weekly

    Automated alerts flag known vulnerabilities in the code Dunity depends on, every week.

Who else handles data

Dunity runs on five providers. Each only gets what it needs to do its job.

  • ClerkSign-in and sessionsUnited States
  • StripeBilling for your Dunity plan, and the source of your connected account’s payment dataUnited States
  • SupabaseOur database, including encrypted storage for keys and webhook addressesSeoul, South Korea
  • VercelHosting and the scheduled jobs that run retries and remindersUnited States
  • ResendDelivering the emails Dunity sends to you and your customersUnited States

What Dunity doesn’t have yet

  • A SOC 2 report or an ISO 27001 certificate.
  • An independent penetration test.
  • A round-the-clock security team. Dunity is run by one person.

This page will change as those do. Until then, everything above is what you can rely on.

Report a security issue

Email maxfromdunity@gmail.com with what you found and the steps to reproduce it.

Please don’t access or change data that isn’t yours, and give us a reasonable time to fix the issue before sharing details. The same contact is published in security.txt.

Security questions

What people ask before connecting their Stripe account.

Is it safe to connect my Stripe account to Dunity?

Dunity asks for a restricted Stripe key with eight specific permissions, never your full secret key. The key is encrypted at rest and never sent back to a browser, and you can revoke it in Stripe at any time, which cuts off access straight away.

Can Dunity move money or issue refunds?

No. It can retry the charge on an invoice your customer already owes, and apply a credit note for a win-back discount you set up. The key has no permission to create refunds, payouts or transfers.

Does Dunity store card numbers?

No. Stripe never sends full card numbers or security codes to Dunity. For expiry reminders it reads a card’s brand, last four digits and expiry date, and doesn’t store them.

What happens to my data if I disconnect Stripe or close my account?

Disconnecting deletes your restricted key, webhook secret and card-expiry records right away, and removes the webhook Dunity created. Your retry and email history stays until you ask for it to be deleted. When you close your account, its data is deleted within 30 days.

Is Dunity SOC 2 certified?

No. Dunity doesn’t have a SOC 2 report, an ISO 27001 certificate or an independent penetration test yet. This page lists what it does have, so you can judge for yourself.

How do I report a security issue?

Email maxfromdunity@gmail.com with the steps to reproduce it. Please don’t access data that isn’t yours, and give us a reasonable time to fix the issue before sharing details.