What we actually do
with your data.
No badges, no boilerplate. Everything on this page is a thing the code does, written down in plain English — and the last section is the list of things we do not do, because that is the half most security pages leave out.
Getting in, and staying out.
Passwords are hashed with scrypt
We never store your password. It is put through scrypt with a random salt unique to your account, and the check on sign-in is constant-time, so a wrong guess takes exactly as long as a right one.
Sign-in cookies are locked down
The session cookie is httpOnly, so no script on the page can read it; SameSite=Lax, so another site cannot ride it; and served only over HTTPS in production. It expires after 30 days.
Sign-in attempts are rate-limited two ways
Repeated attempts are throttled both by where they come from and by which account they target, so someone working a stolen password list against your address is slowed down even from a thousand machines.
Security events are written down
Failed sign-ins, rate-limit trips, API keys created and revoked, and billing changes are recorded with the account, the endpoint and the time — so a question about what happened has an answer.
The credentials you hand over.
Connecting a service means giving us something that works. Here is what happens to it.
Connected-account secrets are encrypted at rest
When you connect a service, the credentials are encrypted with AES-256-GCM before they touch the database, and decrypted only on the server at the moment a request is made.
No endpoint will read them back to you
There is no way to get a stored secret out of CurateOne — not the encrypted value, not a masked version, not the last four characters. The screen tells you a key is set; it cannot tell you what it is.
Integrations cannot be pointed inward
Every outbound request an integration makes is checked first: private, loopback and cloud-metadata addresses are refused, the name is resolved and every address it resolves to is checked, and each redirect is checked again.
API keys are stored as hashes; webhooks are signed
A developer key is shown once and then kept only as a SHA-256 hash and its last four characters — we could not email it back to you if we wanted to. Webhooks we send carry an HMAC signature so your endpoint can prove the message is ours.
What your visitors get.
Your pages tell the browser what they may load
Every published page ships a rule the browser enforces about where its code and content are allowed to come from, plus a second rule that stops the addresses your visitors are on from leaking to other sites.
Tracking tags are yours to add, and stay inert until consent
A new site has no analytics or advertising tags on it. If you add one, it ships switched off: the browser treats it as plain text until a visitor accepts, so it cannot run on someone who said no.
Your visitor stats are cookieless
Visitor counting sets no cookie and keeps no IP address. A visitor becomes a one-way hash that changes every day, which is why your site can report its traffic without putting a consent banner in front of anyone.
Where it lives, and how it leaves.
- Your projects are stored in MongoDB Atlas. The application and your published sites run on Netlify, which also holds the built files a visitor is served.
- Deleting a project does not destroy it. It comes offline straight away and sits in a bin for 45 days, where you can put it back. Only after that is it gone for good, and you are warned before it happens.
- Your site is stored in an open, documented format rather than a private one — nothing about it is designed to be unreadable outside CurateOne.
We never see your card.
- Subscriptions are taken by Cashfree, our payment processor. Card and mandate details are entered on Cashfree's own page — this system has nowhere to put them, and keeps only the subscription's status and reference.
- Messages from the processor are signature-checked before they are believed, so nobody can fake a payment into your account.
- The merchant of record is AKINO Labs LLP, registered at Flat No. 6 & 7, Natubhai Centre, Vadodara, Gujarat 390007, India. That is the name on your receipt.
The things a badge would cover up.
Saying this is more useful to you than silence, and easier for us to keep true than a logo we would have to defend.
- No SOC 2, ISO 27001 or PCI certificate. We hold none of them and are not going to imply otherwise. Card handling is certified at our processor, not here, because card details never reach us.
- No two-factor sign-in yet. Sign-in is a password or a Google/GitHub account today. Use a long, unique password, and prefer the social sign-in if you already have two-factor on that account.
- No data-residency promise. We are not going to tell you which country your records sit in, because no region is pinned in our configuration and a guess is worse than an admission.
- Fonts are the one thing your site fetches elsewhere. A published site loads its typefaces from a font service. Everything else it asks for is either its own, or something you added.
Found something we have got wrong, or something worth reporting? Tell us — we would rather hear it from you. See also our privacy policy and terms.
Read it, then try it.
Nothing above needs a sales call to verify — start a free site and look at what it ships.
No credit card · Free forever plan · You own the code