The simplest security measure: nothing to steal.
Most security statements describe how a company protects its database. We don't have one. Every tool in the GDPRGard suite is a stateless page with no accounts and no server-side storage — so there's no central store of customer data that could be breached, because it doesn't exist.
That's not a workaround for not having proper security — it's a deliberate minimisation strategy. The fewer places data sits, the fewer places it can leak from.
What we can actually back up.
Specific, verifiable measures — not generic security-page language.
Security we rely on, but don't control.
Three external services touch data as part of how the tools work. We chose each for their own track record, but we don't audit their infrastructure ourselves — for their specific security practices, their own documentation is the authoritative source.
| Service | Security info |
|---|---|
| Anthropic API | Processes the content of what you submit. See Anthropic's Trust Center for their security and compliance posture. |
| Netlify | Hosts our site and serverless functions. See Netlify's Trust Center. |
| Formspree | Receives contact form submissions when you explicitly send one. See Formspree's security page. |
What we haven't done yet.
Same principle as everywhere else on this site: we'd rather tell you what's missing than let you assume we have certifications we don't.
None of this means the tools are unsafe to use for their intended purpose — quick checks and drafts for SMB compliance tasks. It does mean that if your organisation's procurement process requires formal certifications, we don't have them yet. Tell us if you need one; that's exactly the kind of demand that tells us it's time to build it.
Found a security issue?
We don't have a bug bounty program, but we take reports seriously and will respond. Please include "security" in your subject line so it doesn't get lost in general enquiries.
Report a security issue