Cellpy runs on hardened infrastructure providers. Here's how we protect your data, your blocks, and the sites that embed them.
Report a vulnerabilityEvery layer of the stack applies the same principle: least privilege, encrypted everywhere, minimal surface area.
All data is transmitted over TLS 1.2+. Block content, credentials, and session data are encrypted at rest via Cloudflare R2 and Neon's managed PostgreSQL.
We collect only what is necessary to operate the platform. We do not store raw payment card data (Stripe handles all PCI-scoped data), and we never sell your data.
Passwords are stored using bcrypt with a high work factor. SSO via Google and GitHub is supported. API tokens are scoped to an organization and can be revoked at any time.
Block assets are served through Cloudflare's global edge network, providing DDoS mitigation, bot protection, and automatic TLS certificate provisioning for custom domains.
Cellpy is built entirely on trusted cloud infrastructure providers, each handling the security controls they specialise in.
Each provider's security certifications (SOC 2, ISO 27001, PCI DSS) apply to their respective scope.
Every action in Cellpy is scoped. Team members, API tokens, and admin accounts operate in strict isolation from each other.
Team members are assigned roles (owner, designer, marketing member) that control which actions they can perform — publishing, approving, assigning blocks, and managing billing.
Each token is scoped to a specific organization. Tokens can be revoked instantly from the dashboard with no disruption to other tokens or team members.
Business plan teams have a staging environment and a mandatory approval workflow before any block reaches production, reducing the blast radius of accidental or unauthorized changes.
The Cellpy admin panel runs as a separate Next.js application with independent authentication. No admin session credential is shared with or accessible from the user-facing dashboard.
We appreciate security researchers who help us keep Cellpy safe. Please disclose responsibly.
Send details of the issue to security@cellpy.com. Include a description, reproduction steps, and the potential impact. Please do not disclose the issue publicly until we've had a chance to address it.
You'll receive a confirmation that we've received your report and are investigating. We'll keep you informed of our progress.
Once the issue is resolved, we'll work with you on a coordinated disclosure timeline. We credit researchers who report responsibly.
For general support questions, use support@cellpy.com instead.
Cellpy is incorporated and operated in Canada. Our data practices are designed to meet these standards.
General Data Protection Regulation (EU/EEA/UK) — adequacy decision applies
See our Privacy Policy →Enterprise customers and security teams can reach us directly. We're happy to share our infrastructure documentation, data processing agreements, or answer specific compliance questions.