This page describes the security controls currently enabled in PipelineGenie. It is maintained by The Collective Software Group LLC to answer common security and privacy questions. It is not a certification and does not create additional legal obligations beyond our Terms and DPA.
Encryption
- All traffic to the Service is encrypted in transit with TLS 1.2+.
- Customer data is encrypted at rest by our database and storage providers.
- Payment card numbers are never stored on our servers; Stripe handles PCI-scope data.
Access Control
- Row-Level Security (RLS) enforces per-tenant data isolation in the database.
- Roles (owner, admin, agent, buyer, seller) are stored server-side and cannot be elevated from the client.
- Least-privilege administrative access; audit logs are retained.
Hosting
The application runs on Cloudflare Workers with data stored in Supabase (Postgres, Storage, Auth) in the United States. Email is sent via Resend/SendGrid. Payments are processed by Stripe.
Backups & Availability
The database provider performs automated daily backups with point-in-time recovery. The Service targets high availability but does not guarantee a specific SLA outside of enterprise agreements.
Vulnerability Reporting
If you believe you have found a security vulnerability, please email legal@getpipelinegenie.com with a description and reproduction steps. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to remediate it.
Shared Responsibility
You are responsible for keeping your credentials secure, granting access only to authorized team members, and complying with applicable law when you upload client information.