Security & data handling

Trust starts with saying exactly what the beta does.

This page describes controls that are implemented today. It is a product disclosure, not a claim of SOC 2, ISO, government certification, or legal compliance.

1

Approved, authenticated storage

A user must be signed in and hold approved customer workspace access before a document can be stored. Uploaded files are placed in a user-specific storage path, and document records are retrieved by the authenticated owner ID.

2

Verified file intake

The beta accepts a defined set of document formats, rejects files larger than 10 MB, and checks each file signature so its contents match the declared format before storage. File names are normalized before storage.

3

Server-side CPSC credentials

CPSC API credentials are configured as hosted server secrets. They are not placed in the browser interface or returned to signed-in users.

4

Restricted API check

The current CPSC connection is limited to an authorized operator allowlist and reads account and collection metadata only.

5

Submission disabled

The current application has no enabled certificate-submission route. Preparing or exporting a review does not transmit certificate data to the CPSC.

6

Importer-controlled review

CertifyPreflight provides preparation support. The importer and its authorized broker or filing partner remain responsible for reviewing the final information.

7

Operator-managed access

Customer access is granted, suspended, and expired from a protected operator console. A valid sign-in alone does not unlock real-document analysis.

8

Two-step operator protection

Sensitive operator consoles and CPSC connection checks require both an approved operator account and two-step verification through the identity provider.

9

Abuse controls

Public fit checks use a hidden bot field and privacy-preserving request-rate key. Authenticated uploads, workspace saves, applications, support requests, payment-session creation, and selected operator actions are protected by server-enforced request limits.

10

Customer-controlled document deletion

Customers can permanently delete individual documents from their authenticated workspace. The server verifies ownership before deleting both the private file and its record.

11

Private feedback by default

Completion-survey responses are stored with the signed-in customer account for product improvement. A customer may allow follow-up about a possible quote, but nothing is published automatically.

12

Separated intake and payment

A completeness screen may move an eligible Guided Pilot application to payment readiness, but it never makes a compliance determination. Workspace access is activated only after an approved scope and a verified payment event when billing is enabled.

13

Stripe-hosted checkout

Payment-card entry occurs on Stripe-hosted Checkout. CertifyPreflight stores payment status and identifiers needed for reconciliation, not full card numbers. Signed webhook verification activates or updates customer access after Stripe confirms the payment or subscription event.

Beta limitations

Controls still on the roadmap

  • • Automated account-wide retention schedules and verified bulk deletion
  • • Formal organization roles and multi-user administration
  • • Independent security certification and penetration-test reporting
  • • Production certificate submission with explicit approval controls

Questions or deletion requests

Contact the CertifyPreflight operator

Individual files can be deleted directly inside the workspace. Account-wide deletion and other data questions are handled through the private Support form. Do not email sensitive product files.

eric@certifypreflight.com