SECURITY AND TRUST
Built for evidence, run like it.
How we keep every certificate honest, every consumer’s data private, and every account secure.
Independence
- Our only job is an honest record of each lead
- Certificates are recorded by cValue, not by the buyer or the publisher
Tamper evidence
- Every certificate is hashed and signed at the moment of submit
- Timestamped by two independent RFC 3161 authorities
- Anyone can verify it on the public certificate page
Privacy by design
- Form fields are masked by default, except consent fields
- Email and phone stored only as keyed hashes that cannot be reversed
- A ready-made disclosure for publishers’ privacy policies
Security
- Encryption in transit and at rest
- SSO and multi-factor authentication
- Tenant isolation and a full audit log
IN PROGRESSCompliance
- SOC 2 Type I audit in progress
- We’ll share the report as soon as it is issued
Data retention
- Unclaimed certificates deleted after 90 days
- Claimed certificates kept for 5 years
- Legal hold blocks deletion until released
Doing a security review?
We’ll send our security overview, data-flow diagram and standard questionnaire answers.