Encrypted handling
Feedback data, screenshots, and attachments are passed through provider-managed transport and storage protections.
Your clients trust you with their site. You trust ClickCues with their feedback. We hold up our end with scoped access, careful storage handling, and operational controls designed to stay quiet in the background.
Feedback data, screenshots, and attachments are passed through provider-managed transport and storage protections.
Project access is enforced through authentication, membership checks, and database policies instead of broad shared visibility.
Sensitive files are kept behind scoped storage paths and application access checks rather than broad public listings.
ClickCues is built to capture feedback context, not extra marketing tracking around your reviewers.
Security-sensitive flows use protected edge functions, scoped storage checks, and audit-oriented event logging.
Data export and deletion requests, security and privacy questions, and vendor questionnaires all route through one customer-facing security contact.
This section summarizes the support available today for security reviews, procurement, and customer due diligence.
Privileged workflows use scoped role checks, owner-only actions, and verified backend authorization before sensitive changes are applied.
Screenshots and uploads are organized around project ownership instead of one shared file surface.
Project membership and owner-only actions are enforced through database policies and scoped authorization checks.
Security-sensitive workflows include token validation, sanitized rendering, guarded file access paths, and verified webhook handling.
Security and privacy questions, data-processing discussions, and vendor questionnaires all route through one customer-facing security contact.
We describe current controls directly and avoid overstating certifications or review work that is not currently in place.
ClickCues supports modern account access and recovery flows designed to keep authentication straightforward and verifiable.
Security events help owners review sensitive account activity, project changes, and audit history.
Project data is separated through scoped access controls designed to keep workspaces isolated from each other.
Files are organized by project and shown through application access controls tied to the current workflow.
| Component | Technology | How ClickCues uses it |
|---|---|---|
| Authentication | Supabase Auth | Email/password, Google OAuth, password reset, and MFA enrollment flows. |
| Database authorization | PostgreSQL RLS + scoped authorization | Project membership and owner-only access policies for data and audit records. |
| Storage | Supabase Storage | Scoped screenshot, attachment, logo, and avatar storage tied to application access controls. |
| Payments | Stripe | Hosted checkout, billing portal access, and webhook-driven subscription state updates. |
| Sanitization | DOMPurify | Sanitized rendering for rich comment content in the application UI. |
| Transactional email | Resend | Transactional email delivery for account, workspace, and product notifications. |
| Backend actions | Supabase Edge Functions | Protected task, comment, storage, checkout, and notification workflows. |
This is an informational list for buyers and reviewers, not a replacement for a DPA or vendor packet.
Purpose: Authentication, database, storage, and backend function runtime
Data category: Account data, project records, feedback metadata, screenshots, and attachments
Purpose: Subscription billing and customer billing portal
Data category: Billing identity and subscription metadata handled through Stripe-hosted payment flows
Purpose: Transactional email delivery
Data category: Recipient email addresses and transactional message payloads
Not currently certified
ClickCues is not currently SOC 2 certified. We use established infrastructure providers, but their certifications do not make ClickCues independently certified.
Not currently certified
ClickCues is not currently ISO 27001 certified.
Supported
Export and deletion requests can be handled operationally. Contact us to discuss data-processing requirements for your organization.
Card handling delegated to Stripe
Stripe-hosted checkout and billing flows reduce direct payment-card handling inside ClickCues.
Not supported
ClickCues is not designed for protected health information and does not currently offer BAA support.
Independent test not completed
ClickCues performs internal security testing. We do not currently claim a completed independent third-party penetration test.
No. ClickCues is not currently SOC 2 certified. We use established infrastructure providers, but their certifications do not make ClickCues independently certified.
Project access is controlled through authentication, project membership checks, database policies, owner-only actions, and scoped backend authorization checks.
Screenshots and attachments stay tied to project-scoped workflows and application access controls. Contact us if your team needs current implementation details for a security review.
Yes. The settings flow includes TOTP-based MFA enrollment, verification, and re-verification for sensitive actions when MFA is enabled.
Yes. Security questionnaire requests can be submitted through the ClickCues security contact, and we can discuss data-processing requirements for your organization there as well.
Use the in-product deletion controls where available or email evander@clickcues.com for export, deletion, or security-related data requests. Retention exceptions may still apply for billing, abuse prevention, security review, or legal obligations.
We welcome good-faith reports from customers and researchers. If you spot a potential vulnerability, contact us before disclosing it publicly and we’ll follow up directly as quickly as possible.
Use the links below for security reviews, data-processing questions, vendor questionnaires, or good-faith vulnerability reports. All customer-facing security requests route to the same inbox.