Security is our absolute highest priority. Here are the measures we take to protect and defend the SSLforSaaS platform.
Provider-backed security controls
TLS-protected app and API traffic
Least-privilege infrastructure access
Data & Storage
We protect your data
Customer configuration is stored in managed services with provider-backed encryption and durability controls. We keep recovery and availability claims tied to the infrastructure that is actually deployed.
Managed database storage
Workspace, project, domain, and billing state is stored in MongoDB with provider-managed durability controls.
Encrypted provider storage
AWS, MongoDB, Cloudflare, and Stripe provide managed encryption controls for the data they process.
Scoped data processing
Each provider receives only the data required for application hosting, edge routing, certificate lifecycle, or billing.
Recovery runbooks
Operational recovery and rollback procedures are maintained for provider-backed deployment and provisioning paths.
Privacy
Customer data is limited and provider-scoped
We separate account and billing data from domain-provisioning data. Custom domain names and routing metadata are shared with Cloudflare and AWS only as needed to provision certificates and route traffic; billing data is handled by Stripe.
What we store about your users
Only the information necessary for SSL certificate lifecycle management — specifically the custom domain name — is retained. This data is used exclusively for certificate provisioning, renewal, and re-issuance. We do not build profiles or analytics from your users' domain data.
Logging
We minimize traffic data
SSLforSaaS stores certificate, routing, and operational state needed to run the service. We do not store customer request bodies as product data, while infrastructure providers may process operational metadata needed for delivery, security, and diagnostics.
Request bodies are forwarded to the configured application endpoint, not stored as product content
Operational logs are limited to delivery, security, billing, and troubleshooting needs
Certificate and routing metadata is retained for the active lifecycle and required audit state
Provider processing is documented as part of the service architecture
Encryption
Encrypting data in transit
The app, API, provider callbacks, and customer-facing edge use HTTPS. Supported protocol versions are controlled by the relevant AWS and Cloudflare endpoints.
Modern TLS
Application and API traffic uses provider-managed HTTPS, with TLS policy controlled at AWS and Cloudflare boundaries.
Secure cookies
All session cookies are set with the Secure and HttpOnly flags to prevent interception and XSS access.
Managed edge policy
Cloudflare applies the customer-hostname certificate and edge transport policy used by provisioned domains.
Encrypted provider calls
Connections to Stripe, Cloudflare, AWS, and MongoDB use their authenticated encrypted interfaces.
Infrastructure
Built on AWS and Cloudflare
SSLforSaaS runs application APIs and asynchronous provisioning workflows on AWS, uses Cloudflare for customer-hostname certificates and edge routing, stores application state in MongoDB, and uses Stripe for hosted checkout and subscription billing.
Shared-responsibility infrastructure
Provider certifications apply to the provider services themselves and do not automatically certify SSLforSaaS. Product-level assurance claims are published only when they have current supporting evidence.
AWS Lambda, API Gateway, Step Functions, and SQS provide the application and provisioning control plane
Cloudflare manages customer-hostname certificate issuance and edge delivery
MongoDB stores workspace, project, domain, notification, and lifecycle state
Stripe hosts checkout and handles raw payment-card data
Organization
Organizational security practices
The product separates customer roles, provider credentials, and deployment environments. This page describes controls evidenced by the current application and repository rather than unpublished organizational certifications.
Workspace roles. Owner, Admin, Editor, and Viewer permissions gate customer-facing workspace and project actions.
Two-factor authentication. The customer app supports 2FA, and provider access is managed separately from customer-facing application roles.
Secret boundaries. Provider credentials and signing keys are supplied through deployment configuration and are not exposed through customer-facing APIs.
Session controls. Authentication cookies use secure deployment settings, while automated bypasses are purpose-scoped and environment-limited.
Provider separation. AWS, Cloudflare, MongoDB, and Stripe responsibilities are separated from application role authorization.
Engineering
Engineering & deployment security
The repository includes automated checks and live-dev acceptance paths for authentication, authorization, billing, provider callbacks, and secret handling.
Automated regression testing. Targeted unit, integration, browser, and contract tests cover security-sensitive behavior before release claims are made.
Protected dev acceptance. Provider-backed journeys are verified against the Access-protected dev environment rather than accepted from mock-only browser evidence.
Secret scanning. Release gates scan committed changes for credential patterns and keep sensitive runtime values out of test artifacts.
Operational visibility. Application and provider operations emit scoped logs and status data used for incident diagnosis and lifecycle reconciliation.
Retention is configuration-bound. Log retention follows the active provider and deployment configuration; this page does not promise an unverified fixed duration.
Testing
Testing and responsible disclosure
The repository includes security-focused unit, integration, browser, and secret-scanning gates. We do not claim a current independent penetration-test certification on this page.
Security regression tests
Authentication, authorization, secret handling, provider callbacks, and billing boundaries have automated regression coverage.
Secret and dependency review
Release gates check committed changes for secret exposure and review dependency risk before release claims are made.
Responsible disclosure
Security reports can be sent directly to the published security contact for triage and response.
Evidence-led remediation
Confirmed defects are tracked with reproducible evidence, bounded fixes, and regression verification.
Payments
We protect your billing information
Checkout and subscription payments are processed by Stripe. Raw payment-card details are entered on Stripe-hosted pages rather than in SSLforSaaS forms.
We never touch raw card data
SSLforSaaS does not collect or store full card numbers or CVV values. We store Stripe customer, checkout, subscription, invoice, and billing-state identifiers needed to operate the service.
Incident Response
Have a concern? Need to report an incident?
Keeping customer data safe is a top priority and a shared responsibility. Your input and feedback on our security is always appreciated.
Contact our security team
Have you noticed abuse, misuse, an exploit, or experienced an incident? Send urgent or sensitive reports directly to our security address. For non-urgent requests, contact general support.
Our full suite of legal and compliance documents. Security doesn't exist in isolation — it's backed by clear commitments across our terms, privacy practices, and service agreements.