Trust is the whole point of Engado, so keeping your data and your account safe matters to us. This page explains, in plain terms, how we protect the Engado website and application and what to do if you ever spot a problem. It is a summary of our approach, not a guarantee, and our practices evolve as the service grows.

Encryption in transit

The website and application are served over HTTPS, so traffic between you and Engado is encrypted using modern TLS. We do not serve the Service over unencrypted connections.

Reputable infrastructure

We build on established providers rather than rolling our own. The marketing website runs on Cloudflare for hosting, content delivery, and network-level protection. The Engado application is hosted on Netlify, with its database, authentication, and account data on Supabase. Email is handled by Resend, and payments by Stripe. We rely on their security programs alongside our own controls, and we limit each provider to only the data it needs.

Spam and bot defence

Our forms are protected by a bot-detection challenge, and we take active steps to keep automated abuse and spam off the platform. The verified-website model is part of this: every site must verify control of its domain before it can participate, which helps reduce fake accounts and bad actors and makes the network worth being in.

Data minimisation

The safest data is the data we never collect, so we try to gather only what the Service needs. What we do collect, and why, is set out in our Privacy Policy.

Accounts and access

Access to systems and data is limited to the people who need it to operate Engado. You help keep your account secure by using a strong, unique password, keeping your login details private, and telling us promptly if anything looks wrong.

Payments

We do not store your full payment-card details. Billing is handled by Stripe, a specialised payment processor that maintains its own industry-standard, PCI-compliant security.

Reporting a vulnerability

If you believe you have found a security issue, we want to hear from you. Email security@engado.com with enough detail to reproduce the issue. Please give us a reasonable chance to investigate and fix it before disclosing it publicly, and do not access or alter data that is not yours while testing.

We will not pursue action against good-faith security researchers who follow this responsible-disclosure approach and avoid accessing, modifying, downloading, or disrupting data or systems beyond what is reasonably necessary to demonstrate the issue.

No absolute guarantees

No online service can promise perfect security. We take security seriously and work to protect your information, but we cannot guarantee it against every possible threat. If we ever become aware of a breach that affects you, we will act on it and notify you and the relevant authorities as required by law.

Contact us

For security questions, reach us at security@engado.com or through our contact page. See also our Privacy Policy and Terms of Service.