Security practices
Practical controls for a consent SaaS — not vague “enterprise-grade” claims.
Encrypted in transit
Dashboard and public APIs are served over HTTPS/TLS. Consent events and account traffic are encrypted between browsers and our servers.
Passwords hashed
Account passwords are stored with bcrypt hashing. We never store plaintext passwords and do not email them back to you.
Least-privilege access
Workspace members only see the owner’s domains. Billing, team management, and MCP tokens stay with the workspace owner. Viewers cannot change settings.
Domain ownership checks
Publishing requires DNS TXT verification so only someone who controls the domain can go live with your embed key.
Rate limiting
Auth, registration, public scan, and MCP endpoints are rate-limited to reduce abuse and automated attacks.
Retention controls
Consent logs are retained according to your plan limits. Paid plans can export CSV for your own audit archive.
Subprocessors
We use a short list of infrastructure providers to host, bill, and email. We do not sell personal data.
| Provider | Purpose | Data involved |
|---|---|---|
| Railway | Application hosting and managed PostgreSQL | Account data, domain settings, consent logs |
| Paddle | Merchant of record for paid subscriptions | Billing email, payment metadata (card details stay with Paddle) |
| Resend | Transactional email (invites, password reset, support) | Email address and message content |
Need a signed DPA for your vendor review? See the Data Processing Agreement or email contact@cmpstack.com.
Report a concern
We aim to reply within 1–2 business days. For security reports, include steps to reproduce and impact.