Security

How CivilDesign AI protects your data. Last updated July 26, 2026.

Encryption in transit

The site is served over HTTPS only. We support TLS 1.3 (with TLS 1.2 as a fallback) and reject the obsolete TLS 1.0/1.1 protocols. Plain HTTP is permanently redirected to HTTPS, and we send an HSTS header so browsers refuse to connect without encryption. Certificates are publicly trusted (Let's Encrypt). You can verify our TLS configuration independently at Qualys SSL Labs.

Encryption at rest

Application data is hosted on DigitalOcean infrastructure in the United States and protected by our hosting provider's physical and platform security controls. Payment card details are never stored on our servers (see Payments, below).

No third-party tracking

We do not run advertising networks, analytics trackers, or third-party scripts. A strict Content-Security-Policy restricts scripts and assets to our own domain. The only cookie we set is an essential, HttpOnly, Secure session cookie used to keep you signed in.

Authentication & access control

Payments

Card payments are processed entirely by Stripe on Stripe-hosted pages (PCI DSS SAQ-A). Card numbers never reach our servers; we store only Stripe's reference identifiers.

Infrastructure

Data deletion

We delete an organization's data on request or on account closure. See our Privacy Policy for details on what we collect and retain.

Compliance

Our controls are designed around the SOC 2 Trust Services Criteria (Security). We are glad to complete security questionnaires and share additional detail with agency IT and security teams — email support@civildesign.ai.

Reporting a vulnerability

If you believe you've found a security issue, please email support@civildesign.ai with the details. We investigate every report and will respond.