Security
How CivilDesign AI protects your data. Last updated July 26, 2026.
Encryption in transit
The site is served over HTTPS only. We support TLS 1.3 (with TLS 1.2 as a fallback) and reject the obsolete TLS 1.0/1.1 protocols. Plain HTTP is permanently redirected to HTTPS, and we send an HSTS header so browsers refuse to connect without encryption. Certificates are publicly trusted (Let's Encrypt). You can verify our TLS configuration independently at Qualys SSL Labs.
Encryption at rest
Application data is hosted on DigitalOcean infrastructure in the United States and protected by our hosting provider's physical and platform security controls. Payment card details are never stored on our servers (see Payments, below).
No third-party tracking
We do not run advertising networks, analytics trackers, or third-party scripts. A strict Content-Security-Policy restricts scripts and assets to our own domain. The only cookie we set is an essential, HttpOnly, Secure session cookie used to keep you signed in.
Authentication & access control
- Each account has its own credentials; passwords are stored only as salted scrypt hashes, never in plain text.
- Two-factor authentication (an authenticator app or emailed one-time codes) is available, and required for new accounts.
- Session cookies are HttpOnly and Secure; you can sign out of all other sessions from your account page.
- Organization data is isolated per tenant — one organization cannot access another's data.
- Role-based access separates organization owners from members.
Payments
Card payments are processed entirely by Stripe on Stripe-hosted pages (PCI DSS SAQ-A). Card numbers never reach our servers; we store only Stripe's reference identifiers.
Infrastructure
- Administrative access to servers is by SSH key only, with the firewall limited to HTTPS.
- Security patches are applied on a regular cadence.
- Security-relevant events (sign-ins, failed sign-ins, administrative and billing actions) are recorded in a durable audit log.
- We monitor system health and availability.
Data deletion
We delete an organization's data on request or on account closure. See our Privacy Policy for details on what we collect and retain.
Compliance
Our controls are designed around the SOC 2 Trust Services Criteria (Security). We are glad to complete security questionnaires and share additional detail with agency IT and security teams — email support@civildesign.ai.
Reporting a vulnerability
If you believe you've found a security issue, please email support@civildesign.ai with the details. We investigate every report and will respond.