Private preview trust
Security
A private-preview security and trust overview for how Cedria handles access, providers, review links, and operational limits.
These pages are early private preview versions and should be reviewed before public commercial launch. They are not legal advice and do not make compliance certification claims.
Data handling summary
Workspace data stays scoped to authenticated workspace members.
Public review and client portal links show limited review-facing data.
Billing is handled through Stripe-hosted Checkout and Customer Portal when configured.
Email delivery uses the configured email provider for invites, reminders, and digests.
Owners and admins can export workspace data from data controls.
Private preview users should avoid highly sensitive production data for now.
Product security posture
Cedria uses workspace-based access controls, server-side data fetching, provider-hosted auth/billing flows, and guarded admin routes. This page describes the current private preview posture, not a certification or audit result.
Authentication
Authentication is handled through Clerk. Workspace membership and role checks determine who can access campaign work, settings, billing, data controls, feedback inboxes, error logs, and usage metrics.
Database and storage
Workspace data is stored in Postgres through the configured database provider. File uploads use Supabase Storage when configured. Public pages and exports are designed not to display raw storage paths.
Payments and email
Payments and subscription management use Stripe-hosted Checkout and Customer Portal when configured. Email delivery uses Resend or the configured email provider for digests, invitations, reminders, and preference links.
Workspace access controls
Owners/admins can manage sensitive workspace tools such as imports, exports, billing, system readiness, error logs, usage metrics, demo data, and team access. Members use normal campaign workflows.
Public review and client portal links
Public review and client portal links use token-based access for selected review-facing content. They should be shared carefully. These links are designed to avoid exposing internal tasks, budgets, risks, reports, admin analytics, private notes, and raw tokens.
Secret handling
Secret values belong in local or hosted environment configuration, not in the app UI, docs, exports, or logs. System readiness pages show presence/status, not secret values.
Backups and exports
Owners/admins can export workspace data from data controls. Automated external backups and formal retention workflows are not implemented in this foundation. Export files should be stored carefully by workspace owners.
Private preview limitations
No SOC 2, HIPAA, GDPR, enterprise security certification, external audit, automated account deletion, or data processing agreement is claimed here. Those require separate review before broader commercial launch.
Responsible reporting
Report security concerns to the project owner with the route, workspace context, what happened, and reproduction steps if safe. Do not include secrets, raw tokens, webhook signatures, or sensitive production data in reports.
Last updated
July 14, 2026