Security

How we handle your data

Testimoni is built on standard, audited infrastructure. This page is straight about what's in place today and what we're working on next.

Encryption in transit

All traffic to testimoni.io and our APIs uses TLS 1.3. The embed script served to your site is also HTTPS-only.

Isolated workspaces

Every workspace is scoped by ID in every query — one workspace can never read another's testimonials, submissions, widgets, or subscription. Enforced at the database query layer.

Managed infrastructure

Compute runs on Vercel (SOC 2 Type II), our Postgres runs on Supabase (SOC 2 Type II), and object storage runs on Supabase Storage. We don't run our own servers.

Auth via Supabase Auth

Password hashing, session management, and Google OAuth are handled by Supabase Auth. Sessions live in HTTP-only cookies; we never touch raw tokens.

PCI-compliant payments

Card details are entered directly into Razorpay's checkout modal — the numbers never touch our servers. Razorpay is PCI DSS Level 1 certified.

Minimal data collection

We store what's needed to run the product: your account, your workspace's testimonials, and your subscription. No third-party analytics tracking your customers on your embedded widgets.

What's coming

SOC 2 Type II report (we inherit our subprocessors' certifications today, but our own audit is planned for 2027). GDPR data-export & deletion self-service. Enterprise SSO (SAML). Audit logs.

Need something specific for your compliance review? Email us — we answer within a business day.