cValue.ai
SECURITY AND TRUST

Built for evidence, run like it.

How we keep every certificate honest, every consumer’s data private, and every account secure.

Independence
  • Our only job is an honest record of each lead
  • Certificates are recorded by cValue, not by the buyer or the publisher
Read the independence statement
Tamper evidence
  • Every certificate is hashed and signed at the moment of submit
  • Timestamped by two independent RFC 3161 authorities
  • Anyone can verify it on the public certificate page
See a sample certificate
Privacy by design
  • Form fields are masked by default, except consent fields
  • Email and phone stored only as keyed hashes that cannot be reversed
  • A ready-made disclosure for publishers’ privacy policies
Security
  • Encryption in transit and at rest
  • SSO and multi-factor authentication
  • Tenant isolation and a full audit log
IN PROGRESSCompliance
  • SOC 2 Type I audit in progress
  • We’ll share the report as soon as it is issued
Data retention
  • Unclaimed certificates deleted after 90 days
  • Claimed certificates kept for 5 years
  • Legal hold blocks deletion until released

Doing a security review?

We’ll send our security overview, data-flow diagram and standard questionnaire answers.

Request our security overview