Trust Center
We secure our own platform the way we secure yours.
Selling security audits means holding ourselves to the same bar. Here is exactly how this site is built, hardened, and monitored — and how to report an issue if you find one.
Security posture
What's in place, in plain terms.
Encryption & transport
- TLS 1.3 with HSTS (includeSubDomains, preload)
- Automatic certificate management
- Secrets stored server-side only — never in the client bundle
Application hardening
- Nonce-based Content-Security-Policy (no unsafe-inline)
- Full header set: X-Content-Type-Options, Referrer-Policy, Permissions-Policy, frame-ancestors 'none'
- Zod input validation on every API route + output sanitisation
Abuse prevention
- Per-IP rate limiting on contact, payment, and lead endpoints
- Turnstile (privacy-friendly) challenge + honeypot on forms
- Webhook signature verification for all payment events
Compliance
Standards we hold ourselves to.
ISO 9001
Certified
Quality management
DPDPA 2023
Compliant
India data-protection
GDPR
Aligned
EU personal-data handling
OWASP
Self-tested
Top 10 + API Top 10 pass before launch
Your data
Privacy by design.
- We collect only what a request needs, store it in the EU/India region, and never sell it.
- You can request access or deletion of your data at any time — see our Privacy Policy.
- Cookie use is minimal and consent-gated for analytics.
Sub-processors
Who we rely on.
| Vercel | Hosting & edge delivery |
| Cloudflare | DNS, WAF & DDoS protection |
| Razorpay / Stripe | Payment processing (no card data stored by us) |
| HubSpot | CRM & lead management |
| Upstash | Rate-limiting store |
Found a vulnerability?
We welcome responsible disclosure. Email security@sitelytc.com with details and steps to reproduce. We aim to acknowledge within 48 hours and will credit valid reports.
A machine-readable policy is published at /.well-known/security.txt.