1. Encryption
Your data is encrypted in two places that matter: while it moves, and while it rests.
- In transit. Every connection to Hostly uses HTTPS with modern TLS. Data moving between your browser, our app, and our providers is encrypted the whole way.
- At rest. Your account and review data sit in our database, hosted by Supabase, encrypted at rest. Backups are encrypted too.
2. Who can see your data
Access to production systems is limited to the small number of people who need it to run and support Hostly. We follow a least-privilege approach, which means people get the access their job requires and nothing more.
- Row-level security. Our database uses row-level security, so the app can only ever read and write the rows that belong to your account. One customer's data cannot leak into another customer's view.
- Scoped keys. The keys our systems use to talk to each other are scoped to what they need and are kept out of our code and out of public view.
- Support access. When we help you, we look only at what we need to solve your issue.
3. How we sign you in
Hostly does not use stored passwords. Instead, we email you a one-time sign-in code when you log in. There is no password for anyone to guess, reuse, or steal in a breach somewhere else. Keep your email account secure, since that is where your sign-in codes arrive.
4. Card data and payments
We never see or store your card number.
Payments run through Stripe, a certified payment processor. When you enter your card, it goes straight to Stripe. Hostly's servers only ever see billing metadata, such as the last four digits, the card brand, and whether a charge succeeded. Card security is handled by Stripe, which specializes in exactly that.
5. Where your data lives
Hostly runs on established United States cloud infrastructure. The website and our serverless functions are hosted by Netlify. Our database and sign-in system are hosted by Supabase in its United States East region. Review drafting is done through Anthropic's Claude API. The full list of providers, what each one does, and where it operates is in our Privacy Policy.
6. If something goes wrong
No system is perfectly secure, and we will not pretend otherwise. If a security breach affects your personal information, we will tell you without undue delay, and no later than 72 hours after we confirm it, unless the law directs us to wait. We will tell you what happened, what information was involved, and what we are doing about it, and we will notify any authority the law requires us to notify.
7. Reporting a vulnerability
If you find a security problem in Hostly, we want to hear about it. Email hello@hostly-reviews.com with the words "Security report" in the subject line, and describe what you found and how to reproduce it.
- We will acknowledge your report and look into it.
- Please give us a reasonable chance to fix the issue before you share it publicly.
- Please do not access, change, or delete data that is not yours, and do not run tests that degrade the service for other people.
We are grateful to researchers who report issues responsibly and help us keep Hostly safe.
8. What we do not claim
We would rather be plain than oversell. Hostly is a small, focused product from Vero Dawn. We do not currently hold a SOC 2 report or ISO 27001 certification, and we will not claim ones we do not have. Our security rests on the practices described on this page and on the certified infrastructure providers we build on, including Supabase, Netlify, and Stripe. If we earn a formal certification in the future, we will say so here.
9. How to reach us
Hostly, a product of Vero Dawn
PO Box 5093
Mooresville, NC 28117
United States
hello@hostly-reviews.com
Any question about how we protect your data, send it here and a real person will answer.