3 waiting on you
last pass7d ago
open7 charges
at risk$1.7k/mo
stopped4
recovered$967
kill window30 s
cap4 of 15
$9/monthConnect Stripe
On this page

Security

a copy of /security, taken 2026-09-13

What CardChase stores, who else processes it, and how to report a vulnerability.

Reporting a vulnerability

Email hello@thecompound.tech. Include the URL, what you did, and what you saw. There is no bounty and no NDA to sign. We will confirm receipt, and we will tell you what we changed.

The same address, with a machine-readable expiry, is published at /.well-known/security.txt under RFC 9116.

Accounts

CardChase has user accounts. What is stored against one, and who else touches it, is below.

What is stored

Who else processes data

Also true

CardChase is built and run by Compound Labs. The declarations on this page are part of this product's own configuration and are re-checked at every deploy against the repository they describe: a product that claims to have no accounts and ships an authentication route fails the build, and so does one that takes payment without naming its payment processor here.

This page is https://cardchase.thecompound.tech/security, word for word, captured 2026-09-13.

WHEN THE LADDER CHANGES

CardChase reads last night's failed charges, stages the retries and stops the ones that will not recover. Which rungs it will stage and how long the kill window runs both change. Leave an address and CardChase writes when they do.

CardChase

Sign in

Sign in to CardChase.

Use the address your subscription was bought with. The account already exists.

or use your email