Built to be trusted.
Designed to be audited.
We use CodeSec to scan CodeSec. Every security claim on this page is verified by the same platform we ship to you.
Application & Infrastructure Security
SecurityWe apply OWASP Top 10 mitigations, enforce TLS 1.3 everywhere, and scan our own codebase with CodeSec.
- TLS 1.3 encryption in transit
- AES-256 encryption at rest
- OWASP Top 10 mitigations
- Rate limiting & CSRF protection
- Dependency CVE scanning
Privacy-First Data Practices
PrivacyWe collect only what we need, never sell your data, and give you full control with self-service deletion.
- No data selling, ever
- Minimal data collection
- Self-service account deletion
- GDPR-compliant processing
- Opt-out analytics
Compliance & Legal
ComplianceTransparent legal documents, GDPR compliance, and clear user rights — no legalese runaround.
- GDPR data rights support
- Clear terms of service
- Startup-friendly refund policy
- Cookie consent management
- Data Processing Agreements
Reliable Infrastructure
InfrastructureBuilt on Supabase, Vercel, and Hetzner Cloud with automated backups, PITR, and row-level security.
- Supabase PostgreSQL (SOC 2 Type II)
- Automated backups with PITR
- Row-level security policies
- Private network isolation
- Multi-region redundancy
Compliance & Certifications
Supabase SOC 2 Type II
Database infrastructure
PCI-DSS via Dodo Payments
Payment processing
GDPR Compliant
EU data protection
TLS 1.3
All connections encrypted
Sub-Processors
All third-party services that process data on behalf of CodeSec users.
| Provider | Purpose | Location | Standard |
|---|---|---|---|
| Supabase | Database, Auth, Storage | SOC 2 Type II | |
| Vercel | Application Hosting | SOC 2 Type II | |
| Hetzner Cloud | Server Infrastructure | ISO 27001 | |
| Dodo Payments | Payment Processing | PCI-DSS | |
| Anthropic | AI Scan Analysis | SOC 2 Type II | |
| OpenAI | AI Scan Analysis | SOC 2 Type II | |
| Resend | Transactional Email | SOC 2 Type II |
Security questions?
Reach out for vulnerability reports, data processing agreements, or any trust-related inquiry.
[email protected]