Skip to main content
Security

Built like the brand pages it ships.

Calm engineering, careful defaults, and zero shortcuts on the things that protect creator data.

Encrypted in transit and at rest

TLS 1.3 for every request. Database, storage and backups encrypted with AES-256.

Server-side entitlement checks

Every billing or feature gate runs on the server. The client is never trusted.

Row-Level Security on every table

Postgres RLS is enabled on day one, even during development. No exceptions.

Token-scoped private shares

Private creator pages issue short-lived tokens with passphrase gates.

Country-level access controls

Creators can restrict their pages to specific countries with edge-evaluated rules.

Quarterly third-party audit

We schedule independent reviews of our auth, billing, and storage flows every quarter.

Audit log for every sensitive action

Sign-ins, password changes, page visibility changes, and admin actions are append-only.

Verified outbound email

DKIM, SPF and DMARC aligned. Bounce and complaint handling on every send.

Compliance posture

Practical, transparent, and honest about where we are on the journey.

GDPR

Compliant. Data subject requests handled within 30 days.

CCPA

Compliant. Sale opt-out is irrelevant, we never sell user data.

SOC 2 Type II

In progress. Targeting completion before public launch.

Found a security issue? Email security@kitpager.pro , we respond within 24 hours and credit responsible disclosure in our changelog.

Security, frequently asked

Where is my data stored?
Creator data lives in a Postgres database hosted on Supabase, encrypted at rest with AES-256 and fronted by TLS 1.3 in transit. Backups are encrypted with the same key material and stored in a separate region. Object storage for media uses the same posture.
Do you share my data with brands or third parties?
We never sell creator data. The only third parties that see your public kit are the brands you choose to share your link with, plus the platform integrations you explicitly connect (TikTok, Instagram, YouTube, Google Calendar, Polar for billing). AI pitch generation runs on your verified stats and past collaborations only, nothing is shared with third-party AI training pipelines.
How do you protect my social media tokens?
OAuth tokens are stored encrypted in our database and never sent to the client. Every API call to TikTok, Instagram or YouTube is made from our server, so the token is never exposed to a browser extension, a malicious script, or a phishing page. Token scopes are the minimum required to verify stats and refresh analytics.
Can I delete my account and data?
Yes. From your account settings you can request a full account deletion, which removes your profile, social tokens, analytics, and uploads within 30 days. A small audit trail (your billing history) is retained for tax and legal reasons, and is clearly labeled in the privacy policy.
How do I report a security issue?
Email security@kitpager.pro with a description and reproduction steps. We respond within 24 hours and credit responsible disclosure in our changelog. A formal bug bounty program is on the roadmap.

Ready to look the part?

Build a brand-ready kit in five minutes. Free forever, upgrade when you book.