Security
What we actually do.
Described plainly, and limited to what is true today.
Your money
We never see your card.
Payments are handled entirely by Stripe. Card details are entered on Stripe's own page and stored by Stripe. They are never sent to us, and we could not retrieve them if we wanted to.
Changing your card, downloading invoices and cancelling all happen in Stripe's own billing portal for the same reason.
Your account
There is no password to steal.
Signing in works by emailed link. We do not store passwords, because we do not have any — so there is nothing to leak in a breach and nothing you might be reusing from somewhere else.
Each link works once and expires after thirty minutes.
Your website
Fewer moving parts, fewer ways in.
Your site is served as plain files. There is no content management system, no plugins and no admin login on it — which removes the way the large majority of small business websites actually get compromised.
Every site is served over HTTPS with a certificate that renews automatically. There is no third-party tracking, no advertising code and nothing loaded from anyone else's server.
Your visitors
We don't track the people who visit you.
Visitor numbers are counted on our own server. There are no cookies and no third-party analytics, which is also why your site doesn't need a cookie banner.
No visitor's IP address is ever written to disk. It is combined with a secret value and turned into an irreversible fingerprint, which lets us tell you how many people visited and how many came back, without ever recording who they were.
Messages sent through your contact form are written down before we try to email them to you, so a mail problem on our side can never lose you a customer.
Reporting a problem
If you find something.
A security contact address will appear here before this site is shown to anyone.
Please don't test against a customer's live site. If you need a target, use our demonstration site.
Being straight with you
What we don't claim.
We are a small, new company. We do not hold SOC 2, ISO 27001 or any other certification, and we are not going to imply otherwise by decorating this page with badges.
What is written above is what we do. If something on this page ever stops being true, it comes off the page.