Data & Storage
We protect your data
We store the workspace, project, domain, and billing information needed to run SSLforSaaS. Managed storage and access controls help protect that information.
Stored configuration
We retain account, project, domain, and billing records needed to provide the service.
Managed storage
Stored application data uses managed encryption and durability controls.
Limited sharing
Domain and routing details are used to issue certificates and deliver traffic; payment details are handled during hosted checkout.
Access controls
Workspace roles and project API keys help limit changes to project and domain settings.
Privacy
How customer data is used
Domain names and routing details are used to provision certificates and direct traffic to your application. Stripe handles checkout and subscription payments.
What we store about your users
We use the custom domain name and its DNS and certificate status to set up and maintain SSL. Account and billing records are described separately above. We do not build profiles of your end users from their domain names.
Logging
We minimize traffic data
SSLforSaaS stores certificate, routing, and operational state needed to run the service. We do not store customer request bodies as product data, while infrastructure providers may process operational metadata needed for delivery, security, and diagnostics.
Request bodies are forwarded to the configured application endpoint, not stored as product content
Operational logs are limited to delivery, security, billing, and troubleshooting needs
Certificate and routing metadata is retained for the active lifecycle and required audit state
Encryption
Encrypting data in transit
The app, API, and provisioned customer domains use HTTPS. Certificate and TLS settings depend on the endpoint.
HTTPS connections
HTTPS protects connections to the app and API.
Secure cookies
All session cookies are set with the Secure and HttpOnly flags to prevent interception and XSS access.
Managed edge policy
Cloudflare applies the customer-hostname certificate and edge transport policy used by provisioned domains.
Service connections
Connections to services used for hosting, certificates, and billing use authenticated encrypted channels.
Infrastructure
Managed SSL infrastructure
SSLforSaaS uses managed hosting and Cloudflare's edge to issue certificates and route traffic for connected customer domains.
Project settings show the DNS target to share with each domain owner
Cloudflare issues and renews certificates for connected customer domains
The app shows DNS validation, certificate, and domain activation status
Active domains forward traffic to the configured application endpoint
Account
Account security
Workspace permissions, two-factor authentication, and secure sessions help protect account actions.
Workspace roles. Owner, Admin, Editor, and Viewer permissions gate customer-facing workspace and project actions.
Two-factor authentication. The customer app supports 2FA for account sign-in.
Project API keys. Owners and Admins can create, rotate, or revoke a key for their project.
Session controls. Customer sessions use secure cookies and role-based authorization.
Payments
We protect your billing information
Checkout and subscription payments are processed by Stripe. Raw payment-card details are entered on Stripe-hosted pages rather than in SSLforSaaS forms.
We never touch raw card data
SSLforSaaS does not collect or store full card numbers or CVV values. We store Stripe customer, checkout, subscription, invoice, and billing-state identifiers needed to operate the service.
Incident Response
Have a concern? Need to report an incident?
Keeping customer data safe is a top priority and a shared responsibility. Your input and feedback on our security is always appreciated.
Contact our security team
Have you noticed abuse, misuse, an exploit, or experienced an incident? Send urgent or sensitive reports directly to our security address. For non-urgent requests, contact general support.
Legal
Additional policies
Our full suite of legal and compliance documents. Security doesn't exist in isolation — it's backed by clear commitments across our terms, privacy practices, and service agreements.