SecurityPlain answers, no theater

Security & data,
answered straight.

Everything on this page is inspectable — the headers this site serves, the database policies behind the portal, and the short list of vendors we run on. If your team has a security questionnaire, send it over and we'll answer it line by line.

01The short version

Small surface. Strict defaults.

  • Encrypted in transit, everywhereTLS on every request; HSTS with preload enforced at the edge.
  • Encrypted at restInquiry data lives in managed PostgreSQL on AWS, encrypted at rest by the platform.
  • Access control in the databaseRow-level security — isolation is enforced by PostgreSQL policies, not application code.
  • No password databasePortal sign-in is passwordless (one-time email links) — there are no credentials to breach.
  • Minimal data, no resaleWe collect only what the contact form asks. We never sell or share data for marketing.
  • Your systems stay yoursClient builds live in your accounts and your tenant — our access is scoped and revoked at handover.
02This website

What happens to data
you give this site.

/ 01

What we collect

Only what the contact form asks: name, work email, company, size, interest, budget range, and your message. A hidden honeypot field and per-connection rate limiting keep bots out. No ad pixels, no fingerprinting.

/ 02

Where it lives

Inquiries are stored in a managed PostgreSQL database (Supabase, AWS ap-northeast-1) with row-level security enabled and no anonymous read or write access. Writes go through one validated intake function — the public key cannot touch the table directly.

/ 03

Who can read it

Two identities: you (portal sign-in with the same email you submitted — you see only your own rows) and the founder's admin login. Both are enforced by database policy, not application logic.

/ 04

Analytics posture

If analytics run on this site they are limited to Google Analytics 4 with IP anonymization and Microsoft Clarity for usage heatmaps — measurement, not ad targeting. Details and your choices are in the privacy policy.

/ 05

Edge protections

Every response ships hardened headers — HSTS with preload, X-Frame-Options DENY, nosniff, a strict referrer policy, and a permissions policy that disables camera, microphone, and geolocation. Verifiable with one curl.

/ 06

Retention & deletion

Inquiry data is kept only while a conversation is live or an engagement requires it — the database is the single store, with no shadow copies in spreadsheets or side tools. Ask for deletion and it's removed from the live system immediately.

03Client engagements

How builds are secured
inside your company.

The systems we build run in your infrastructure, under your ownership — that's the security model. We're operators in your house, not custodians of your data.

/ 01

Your tenant, your ownership

CRM, automations, AI workflows, and dashboards are built in your accounts and workspaces. Nothing critical lives in ours; if we disappeared tomorrow, everything keeps running and you keep every key.

/ 02

Least-privilege access

We request the narrowest access that gets the work done, under named accounts you grant — never shared logins. At handover, access is reviewed and revoked, and the SOPs document every credential the system uses.

/ 03

Confidentiality by default

NDAs are standard before we see your pipeline. Client data isn't used to train AI models without your written consent, and AI components are configured in your accounts under the same rule.

/ 04

Documented, auditable, reversible

Every workflow ships documented: what it touches, what data flows where, and how to switch it off. Your team can audit the whole machine without us in the room.

04Vendor stack

Every third party, listed.

This site runs on a deliberately short list. Each vendor sees only what its job requires.

Hosting

Vercel

Serves these static pages over TLS with the hardened headers above. Sees standard web server logs.

Database & auth

Supabase (AWS)

Managed PostgreSQL and passwordless sign-in, hosted on AWS (Tokyo). Holds inquiry data, encrypted at rest, behind row-level security.

Email

Resend

Delivers transactional email only — sign-in links, inquiry confirmations. No marketing lists, no tracking pixels in our mail.

Scheduling

Cal.com

Handles call booking with timezone detection, confirmations, and reminders. Sees the details you enter when booking.

Fonts

Google Fonts

Serves the two typefaces on this site. Standard font-delivery request logs only.

Analytics (optional)

GA4 & Clarity

Usage measurement when enabled — GA4 with IP anonymization, Clarity for heatmaps. Never ad retargeting.

05Your rights & our claims

GDPR requests — and what
we don't claim.

Your data, your call

  • Access & exportEmail us and we'll send everything we hold about you.
  • Erasure, honoredAsk and your inquiry data is deleted — no dark patterns, no delays.
  • DPA on requestWorking with EU data? We'll sign a data processing agreement.
  • One address for all of itumang@cirvix.com — replies within one business day.

Said plainly

  • No SOC 2 or ISO 27001 badge — yetWe're a young firm and won't imply an audit we haven't passed. The controls on this page are real and small enough to verify in one call.
  • No compliance theaterWe'd rather show you the actual RLS policies and headers than a wall of borrowed badges.
  • Found something?Report security concerns to the same address — we take them seriously and reply fast.
06Enterprise & procurement

Built to clear
your vendor review.

The questions a procurement and security team ask before a six-figure signature — answered before you ask them.

/ 01

The contracts we sign

A mutual NDA before we see your pipeline, a Master Services Agreement per engagement (fixed scope, acceptance criteria, and an agreed liability framework), and a Data Processing Agreement wherever EU data is involved. All IP created is assigned to you — accounts, code, prompts, and documentation are in your name from day one. Your paper or ours.

/ 02

Identity & access

We build inside your identity and access model — named, least-privilege accounts provisioned through your IT (SSO / SAML, your identity provider, conditional access), used only for the build and revoked at handover. The systems we build authenticate through your existing controls, never a side door.

/ 03

Data residency, your choice

Client systems run in the accounts, cloud, and region you choose — your tenant, your residency requirements. We adapt to where your data is allowed to live, not the other way around.

/ 04

Business continuity

Founder-led is a quality choice, not a single point of failure we've ignored. Everything we build lives in your tenant and is documented as we go — SOPs, runbooks, kill switches — so your team or any competent operator can carry it forward. Milestone-based payment means you never pre-pay for undelivered work; everything delivered is already yours.

Have a security questionnaire, DPA, or insurance requirement? Send it over — we answer line by line and meet what the engagement genuinely needs.

Send us your security questionnaire.

We'll answer it line by line — the fastest way to find out we have nothing to hide.

Or book a call and ask everything live — contact