Foundations
End-to-end encryption
All data encrypted in transit (TLS 1.3) and at rest (AES-256). Every page is HTTPS via Cloudflare with HSTS preloading.
Strict tenant isolation
Multi-tenant database with retailer-scoped access controls. Retailer A cannot read retailer B's data, even via API leaks.
No passwords
Magic-link authentication only. No passwords to leak, phish, or reuse from other breached sites.
Privacy-respecting analytics
Session replay enabled with PII masking. Email addresses, file uploads, and document URLs never leave your browser unmasked.
Privacy commitments
- ✓We never sell your data.
- ✓We never share your data with other retailers without your booking action.
- ✓We don't train AI models on your data.
- ✓You can export everything as JSON anytime.
- ✓You can delete your account anytime; data purged within 30 days.
- ✓GDPR (EU/UK) and CCPA (California) rights guaranteed.
Infrastructure
We use industry-standard infrastructure to host your data and run the service:
- ✓Vercel , application hosting (SOC 2 Type 2, ISO 27001)
- ✓Supabase , database + file storage (SOC 2 Type 2, US-West region)
- ✓Cloudflare , CDN, DDoS protection, TLS (SOC 2 Type 2, ISO 27001)
- ✓Stripe , payments (PCI DSS Level 1)
- ✓Resend , transactional email (SOC 2 Type 2)
- ✓PostHog , product analytics with masking (SOC 2 Type 2, GDPR)
See our full subprocessor list for details.
Compliance roadmap
We're a young company building toward enterprise-grade security:
- ✓Today: Foundational hygiene complete (encryption, isolation, magic-link auth, privacy policy, terms of service)
- ✓Q3 2026: Independent code review + audit log infrastructure
- ✓Q4 2026: Penetration test by an outside firm
- ✓Q1 2027: SOC 2 Type 1 audit
- ✓Q3 2027: SOC 2 Type 2 audit
If your organization requires specific compliance documents (DPA, security questionnaire, SCCs), contact david@demohubhq.com.
Responsible disclosure
Found a security issue? We'd like to hear from you. Email david@demohubhq.com with details. We respond within 24 hours, will not pursue legal action against good-faith researchers, and will credit reporters who request it.
Questions?
Privacy: david@demohubhq.com
Security: david@demohubhq.com
Compliance docs (DPA, SCCs): legal@demohubhq.com