Security
How we protect your data
Security is not an afterthought at Winstia — it is built into every layer of the platform, from database row-level isolation to encrypted backups.
AES-256 Encryption
TLS 1.2+ In Transit
GDPR Compliant
CCPA Compliant
99.9% Uptime Target
Encryption everywhere
- All data encrypted at rest using AES-256
- All data in transit encrypted via TLS 1.2+
- Database backups encrypted before storage
- Secret keys stored in environment vaults — never in code
Infrastructure & hosting
- Hosted on Supabase (PostgreSQL) with ISO 27001-certified infrastructure
- Frontend deployed on Vercel Edge Network — 99.9% uptime target
- Hosted on ISO 27001-certified cloud infrastructure
- Automated daily backups with point-in-time recovery
Access controls
- Row-level security (RLS) — each business sees only its own data
- Role-based access control (RBAC) — granular staff permissions
- Multi-factor authentication (MFA) supported
- Session tokens rotated and expire automatically
Vulnerability management
- Dependency scanning on every code push (Dependabot)
- OWASP Top 10 checked during code review
- Security patches applied within 48 hours of disclosure
Incident response
- 24/7 uptime monitoring with automated alerts
- Incident response runbook maintained
- Affected customers notified within 72 hours of confirmed breach (GDPR Art. 33)
- Post-incident reports published for major events
Compliance & roadmap
- GDPR-aligned — data subject rights honored within 30 days
- CCPA compliant — no sale of personal data
- Cookie consent required before analytics activation — analytics off by default
- Data Processing Agreement (DPA) — see winstia.com/dpa or request a countersigned copy — email privacy@winstia.com
Found a vulnerability?
We take security reports seriously and respond within 48 hours. Please disclose responsibly — do not publish details publicly until we have had a chance to fix the issue.
security@winstia.com