Security & trust
Beyond our own systems, just two companies process your data: our host and our payment processor.
That's the whole list (Cloudflare for hosting, Polar for payments — analytics are self-hosted). Most SaaS leak your data across 8–15 subprocessors and a wall of ad pixels. websideproject is built so there's almost nothing to leak.
Infrastructure
Hosted entirely on Cloudflare — Workers for compute, D1 for the database, R2 for files, all behind Cloudflare's network. Hosted in the EU region where available.
Encryption
Encrypted in transit (TLS 1.3) and at rest (AES-256). Sessions use Secure, HttpOnly, SameSite cookies; secrets are never committed to source control.
Cookieless analytics
Analytics are self-hosted and cookieless (Umami). No third-party trackers, no cross-site profiles. Guests can opt out, and identifiers are cryptographically unlinkable after account deletion.
Real deletion
Account deletion is cryptographically real: per-subject keys are shredded so the data becomes permanently unreadable — even in backups — not just flagged "deleted".
Backups
The database is backed up daily to versioned object storage.
Audit trail
A real, append-only audit log records security-relevant actions — and the relevant slice is visible to you in your own settings, not hidden away.
No trackers, ever
No ad pixels, no marketing SDKs, no data brokers. Blog, docs, feedback, roadmap, changelog, newsletter and forms are all built in — not bolted-on third parties that widen the breach surface.
One payment processor
Billing runs through a single merchant of record (Polar). We never see or store raw card data.
Subprocessors
The complete list of companies that may process your data on our behalf.
Hosting, edge compute (Workers), database (D1), object storage (R2), CDN & DNS.
Data: Account data, Application data, IP addresses (transient), Request logs
EU region where available (configurable per deployment)
DPA ↗Payments, subscriptions & invoicing (merchant of record).
Data: Billing contact, Email, Payment metadata (no raw card data)
United States / EU
DPA ↗Cookieless, first-party product analytics. No data leaves your infrastructure.
Data: Pseudonymous page/event data (no cookies, no cross-site tracking)
Same region as the app (self-hosted)
Why we don't (yet) have SOC2
SOC2 audits whether you documented a process — not whether your product is actually private. Plenty of SOC2-certified apps still run ad pixels, share data with a dozen subprocessors, and fake account deletion. We'd rather spend the effort on the architecture above.
We'll pursue SOC2 the moment a customer genuinely needs it — at which point it's mostly documenting what you can already read on this page. Until then, the controls are real and independently verifiable in the product (your audit log, your data export, your deletion).
Reporting a vulnerability
Found something? Email security@websideproject.com. We aim to acknowledge within 48 hours. Our machine-readable policy lives at /.well-known/security.txt.