Built like the brand pages it ships.
Calm engineering, careful defaults, and zero shortcuts on the things that protect creator data.
Encrypted in transit and at rest
TLS 1.3 for every request. Database, storage and backups encrypted with AES-256.
Server-side entitlement checks
Every billing or feature gate runs on the server. The client is never trusted.
Row-Level Security on every table
Postgres RLS is enabled on day one, even during development. No exceptions.
Token-scoped private shares
Private creator pages issue short-lived tokens with passphrase gates.
Country-level access controls
Creators can restrict their pages to specific countries with edge-evaluated rules.
Quarterly third-party audit
We schedule independent reviews of our auth, billing, and storage flows every quarter.
Audit log for every sensitive action
Sign-ins, password changes, page visibility changes, and admin actions are append-only.
Verified outbound email
DKIM, SPF and DMARC aligned. Bounce and complaint handling on every send.
Compliance posture
Practical, transparent, and honest about where we are on the journey.
GDPR
Compliant. Data subject requests handled within 30 days.
CCPA
Compliant. Sale opt-out is irrelevant, we never sell user data.
SOC 2 Type II
In progress. Targeting completion before public launch.
Security, frequently asked
- Creator data lives in a Postgres database hosted on Supabase, encrypted at rest with AES-256 and fronted by TLS 1.3 in transit. Backups are encrypted with the same key material and stored in a separate region. Object storage for media uses the same posture.
- We never sell creator data. The only third parties that see your public kit are the brands you choose to share your link with, plus the platform integrations you explicitly connect (TikTok, Instagram, YouTube, Google Calendar, Polar for billing). AI pitch generation runs on your verified stats and past collaborations only, nothing is shared with third-party AI training pipelines.
- OAuth tokens are stored encrypted in our database and never sent to the client. Every API call to TikTok, Instagram or YouTube is made from our server, so the token is never exposed to a browser extension, a malicious script, or a phishing page. Token scopes are the minimum required to verify stats and refresh analytics.
- Yes. From your account settings you can request a full account deletion, which removes your profile, social tokens, analytics, and uploads within 30 days. A small audit trail (your billing history) is retained for tax and legal reasons, and is clearly labeled in the privacy policy.
- Email security@kitpager.pro with a description and reproduction steps. We respond within 24 hours and credit responsible disclosure in our changelog. A formal bug bounty program is on the roadmap.
Where is my data stored?
Do you share my data with brands or third parties?
How do you protect my social media tokens?
Can I delete my account and data?
How do I report a security issue?
Keep exploring
Ready to look the part?
Build a brand-ready kit in five minutes. Free forever, upgrade when you book.