Security & Reporting
Last updated July 2, 2026
Template — this document was drafted for LMI-OS and is pending review by LMI leadership and, where appropriate, legal counsel. It describes current practice in good faith but is not legal advice.
How we protect your data
- All traffic is encrypted in transit (HTTPS).
- Row-level security in the database restricts every record to the people who should see it — private messages to their participants, submissions to their owner and graders, quiz answer keys to the server only.
- Admin capabilities require exec roles enforced on the server, not just hidden in the interface.
- Sensitive admin actions (role changes, grading, point adjustments, deletions) are logged.
- Passwords are managed by Supabase Auth; LMI never sees or stores them.
Reporting a vulnerability
If you find a security issue in LMI-OS, please email longhornmacroinvestors@gmail.com with enough detail to reproduce it. Give us a reasonable window to fix it before sharing publicly. We will not pursue action against good-faith security research that respects member privacy and avoids service disruption.
If something goes wrong
Suspected account compromise, exposed data, or abuse: contact longhornmacroinvestors@gmail.com immediately. The exec team will investigate, revoke affected access, and notify impacted members.