CMPStackCMPStack
Security

How we protect your data

CMPStack processes account credentials, domain settings, and consent events on your behalf. This page explains the controls we apply and who helps us operate the platform.

Security practices

Practical controls for a consent SaaS — not vague “enterprise-grade” claims.

Encrypted in transit

Dashboard and public APIs are served over HTTPS/TLS. Consent events and account traffic are encrypted between browsers and our servers.

Passwords hashed

Account passwords are stored with bcrypt hashing. We never store plaintext passwords and do not email them back to you.

Least-privilege access

Workspace members only see the owner’s domains. Billing, team management, and MCP tokens stay with the workspace owner. Viewers cannot change settings.

Domain ownership checks

Publishing requires DNS TXT verification so only someone who controls the domain can go live with your embed key.

Rate limiting

Auth, registration, public scan, and MCP endpoints are rate-limited to reduce abuse and automated attacks.

Retention controls

Consent logs are retained according to your plan limits. Paid plans can export CSV for your own audit archive.

Subprocessors

We use a short list of infrastructure providers to host, bill, and email. We do not sell personal data.

ProviderPurposeData involved
RailwayApplication hosting and managed PostgreSQLAccount data, domain settings, consent logs
PaddleMerchant of record for paid subscriptionsBilling email, payment metadata (card details stay with Paddle)
ResendTransactional email (invites, password reset, support)Email address and message content

Need a signed DPA for your vendor review? See the Data Processing Agreement or email contact@cmpstack.com.

Report a concern

We aim to reply within 1–2 business days. For security reports, include steps to reproduce and impact.

contact@cmpstack.com