Trust & Security

Built to be trusted

Cellpy runs on hardened infrastructure providers. Here's how we protect your data, your blocks, and the sites that embed them.

Report a vulnerability
Core principles

Security by default

Every layer of the stack applies the same principle: least privilege, encrypted everywhere, minimal surface area.

Encrypted in transit and at rest

All data is transmitted over TLS 1.2+. Block content, credentials, and session data are encrypted at rest via Cloudflare R2 and Neon's managed PostgreSQL.

Minimal data collection

We collect only what is necessary to operate the platform. We do not store raw payment card data (Stripe handles all PCI-scoped data), and we never sell your data.

Hardened authentication

Passwords are stored using bcrypt with a high work factor. SSO via Google and GitHub is supported. API tokens are scoped to an organization and can be revoked at any time.

CDN delivered by Cloudflare

Block assets are served through Cloudflare's global edge network, providing DDoS mitigation, bot protection, and automatic TLS certificate provisioning for custom domains.

Infrastructure

We don't run our own servers

Cellpy is built entirely on trusted cloud infrastructure providers, each handling the security controls they specialise in.

ProviderRoleRegion
Cloudflare R2Block asset storage and CDN deliveryGlobal edge
Cloudflare for SaaSSSL certificates for custom CDN domainsGlobal edge
VercelWeb application and API hostingGlobal (serverless)
NeonPostgreSQL database (user data, metadata)AWS us-east-1
StripePayment processing and Marketplace payoutsUS / global

Each provider's security certifications (SOC 2, ISO 27001, PCI DSS) apply to their respective scope.

Access controls

Fine-grained, revocable access

Every action in Cellpy is scoped. Team members, API tokens, and admin accounts operate in strict isolation from each other.

Role-based permissions

Team members are assigned roles (owner, designer, marketing member) that control which actions they can perform — publishing, approving, assigning blocks, and managing billing.

Personal API tokens

Each token is scoped to a specific organization. Tokens can be revoked instantly from the dashboard with no disruption to other tokens or team members.

Staged publishing

Business plan teams have a staging environment and a mandatory approval workflow before any block reaches production, reducing the blast radius of accidental or unauthorized changes.

Admin isolation

The Cellpy admin panel runs as a separate Next.js application with independent authentication. No admin session credential is shared with or accessible from the user-facing dashboard.

Data practices

What we store and why

PasswordsHashed with bcrypt. We never store or log plaintext passwords.
Payment dataCellpy never stores payment card details. All billing data is held by Stripe under PCI DSS.
Block contentHTML and CSS is stored in Cloudflare R2 and served over encrypted CDN connections. Block content is not inspected or indexed by Cellpy.
CDN request logsIP addresses, URLs, and HTTP headers are logged for up to 90 days for security monitoring and abuse prevention, then deleted.
VS Code telemetryUsage events (publish actions, timestamps) are collected to improve the extension. The HTML/CSS content of blocks is never included. Telemetry can be disabled in extension settings.
Session tokensEncrypted, HttpOnly cookies with short expiry. Sessions are invalidated on password change and on logout.
Responsible disclosure

Found a vulnerability?

We appreciate security researchers who help us keep Cellpy safe. Please disclose responsibly.

01
Email us privately

Send details of the issue to security@cellpy.com. Include a description, reproduction steps, and the potential impact. Please do not disclose the issue publicly until we've had a chance to address it.

02
We'll acknowledge within 3 business days

You'll receive a confirmation that we've received your report and are investigating. We'll keep you informed of our progress.

03
Coordinated disclosure

Once the issue is resolved, we'll work with you on a coordinated disclosure timeline. We credit researchers who report responsibly.

Contact security@cellpy.com

For general support questions, use support@cellpy.com instead.

Compliance

Legal and regulatory alignment

Cellpy is incorporated and operated in Canada. Our data practices are designed to meet these standards.

PIPEDA

Personal Information Protection and Electronic Documents Act (Canada)

See our Privacy Policy →
PIPA (Alberta)

Alberta Personal Information Protection Act

See our Privacy Policy →
GDPR

General Data Protection Regulation (EU/EEA/UK) — adequacy decision applies

See our Privacy Policy →

Security questions?

Enterprise customers and security teams can reach us directly. We're happy to share our infrastructure documentation, data processing agreements, or answer specific compliance questions.

security@cellpy.comPrivacy Policy