Trust & Security
How we protect your account, your data, and your trades. This page is maintained by RL Group Asia and reflects the controls we operate today — it is not an independent certification.
Data protection
All traffic is served over HTTPS. Sensitive fields such as supplier inquiry emails are restricted at the database layer and never returned to the public product feed.
Row-Level Security policies scope every table to its owner or to roles that need access.
Account security
Sign-in supports email + password (minimum 8 characters), Google OAuth, and phone OTP. Administrator access is gated by a server-side role check and a separate admin sign-in page.
Roles are stored in a dedicated table; users can never self-assign administrator privileges.
Infrastructure
Hosted on Lovable Cloud with managed Postgres, authentication, and storage. Storage buckets holding verification documents and product images are private and accessed via short-lived signed URLs.
Payments & membership
Membership payments are reviewed and approved by an administrator before access is granted. Card validity is tracked day-by-day and access is automatically revoked when a card expires unless the buyer renews.
Secure payment coordination for B2B trade orders is provided manually by the RL Group Asia team. Managed escrow and milestone-release payments are coming soon for eligible verified orders.
Reporting a vulnerability
If you believe you have found a security issue, please email security@rlgroupasiath.com with steps to reproduce. Please do not publicly disclose the issue until we have had a chance to investigate.
Privacy & legal
See our Privacy Policy, Terms of Service, and Trade Assurance for details on how we handle data and protect transactions.
Last updated 1 August 2026.
