Security Overview & Subprocessor Registry
We design every layer of ComplyWCAG with strict privacy-by-default principles, strong encryption, and complete transparency about our vendors and data handling.
Encryption Everywhere
All data in transit is protected with modern TLS 1.3 encryption with HSTS enabled. Data at rest is encrypted using AES-256 standard encryption.
Zero PII Visitor Telemetry
Our widget runtime never transmits IP addresses, full user-agent strings, query parameters, or form contents to our servers. We never store visitor health or disability status.
Strict Row-Level Security
Our database enforces granular PostgreSQL Row Level Security (RLS) policies ensuring customers can only access their authorized organization data.
Authorized Subprocessor Register
ComplyWCAG engages the following third-party subprocessors to deliver core infrastructure, security, and billing services:
| Subprocessor | Service & Purpose | Location | Data Processed |
|---|---|---|---|
| Supabase Inc. | Managed PostgreSQL Database, User Auth, and Storage | United States (AWS us-east-1) | Account credentials, website configuration |
| Stripe Inc. | Payment Processing & Billing Subscription Management | United States | Payment tokens, billing customer records (PCI-DSS Level 1 compliant) |
| Vercel Inc. | Application Edge Server Hosting & Global Edge CDN | Global Edge Network | Server access logs, static widget asset delivery |
Vulnerability Disclosure Policy
We welcome responsible security disclosures from researchers. If you believe you have discovered a vulnerability, please report it to our security team directly:
RFC 9116 security manifest is published at /.well-known/security.txt.
Data Processing Agreement (DPA)
We offer a comprehensive Data Processing Agreement (DPA) incorporating EU Standard Contractual Clauses (SCCs) and UK IDTA for enterprise and business customers.