Security
What we protect, and what we do not claim
This page describes the Cecur account portal at cecur.io: the data we hold, the companies we rely on to run it, how access is controlled, and the controls we do not have. Everything here was checked against the running system. Where a control does not exist, we say so rather than leave you to assume it does.
Last reviewed: August 2026
Which system this covers
Accounts, teams, billing and support live here at cecur.io. Documents, signatures and the evidence behind them live in CecurSign, which keeps its own security page covering its audit trail, certificate of completion and public verification.
Read the CecurSign security pageWhat we hold
Three categories, and nothing else about you.
Your account
Name, email address, role, status, and when that identity last signed in to any Cecur product. Your password is held by Auth0, our identity provider. There is no password column in our database and we cannot read your password.
Your billing
Billing name, email address, address and country, your VAT number and its validation result, your subscription, usage records and invoices, and a Stripe customer reference. We store the reference, not the card.
What you send us
Contact form submissions, which record the name, email, company and message you type along with the IP address, browser and referring page of the submission, and any support tickets you raise.
We use no analytics and no advertising services on this site. The portal sets two cookies, both from the Auth0 sign-in library, and fonts are served from our own domain rather than fetched from a third party. Our privacy policy sets out your rights over all of it.
Who we rely on
Our own products and internal services, including CecurSign, our notification service and DocVault, are built and run by us. They are not third parties. The outside companies in the path today are these.
| Purpose | Provider | What they handle |
|---|---|---|
| Sign-in and identity | Auth0 (Okta, Inc.) | Names, email addresses, credentials, multi-factor enrolment and sign-in events. |
| Subscription billing and payments | Stripe | Billing identity and subscription state. Card details are entered on Stripe’s own pages and never reach our servers. |
| Delivery of our email | Resend | Names, email addresses and the content of the emails we send you: invitations, verification, invoices and support replies. |
| Managed database hosting | OVHcloud | The portal database. |
| VAT number validation | European Commission VIES | A VAT number and its country. |
We also rent the servers the portal runs on. Ask us and we will tell you who from and where they are. If we take on a new provider that handles your data, this list is where it will appear.
How access is controlled
One organisation cannot see another
Every request carries the organisation of the signed-in user, and account, billing and team data are read and written under that scope. There is no shared view across customers.
Staff access is a separate account
Cecur staff accounts are a different kind of account from a customer account and sit behind their own check. A customer login cannot reach a staff endpoint, and a staff account is not created by signing up.
Staff actions are recorded
Administrative actions are written to an audit log with the actor, the action, the record it affected, the IP address it came from and the time. If you want to know what we did on your account, that is the record we answer from.
Two-factor authentication
You can enrol a second factor when you sign in, and review or remove your enrolled methods afterwards. Enrolment is handled by Auth0, so one enrolment covers every Cecur product you use.
Data in transit
Every request between your browser and our site, and between our site and our API, travels over TLS. So does the connection from our servers to the database, which runs on a managed PostgreSQL cluster and verifies the certificate it is presented with rather than accepting whatever is offered.
Card details are a deliberate exception to everything else on this page: they do not travel to us at all. Payment pages are hosted by Stripe, and what comes back to us is a customer reference and the outcome.
What we do not do
We do not encrypt data at rest, and we are not end to end encrypted. Your data is not held under a separate cipher in our database, and our systems can read what you store. End to end encryption means the provider cannot read the content, and that is not what this is. We would rather tell you than let the phrase sit on a page doing work it cannot do.
We hold no security certifications. No ISO 27001, no SOC 2, no Cyber Essentials. If your procurement process requires a certified supplier, we do not meet it today.
We do not offer an uptime commitment. There is no service level agreement, no published availability figure and no service credits, because there is no monitoring commitment standing behind them.
We do not guarantee where your data is held. Our own servers and databases are hosted in the European Union. That is a statement about where we host, not a guarantee about every piece of data: our email delivery provider is based in the United States, so at minimum the emails we send you involve a transfer there, and we have not yet confirmed the region of our identity provider. We will not claim end to end UK or EU residency until it is true of every provider in the path rather than of our own infrastructure.
We do not run a retention or deletion schedule. Nothing is purged automatically on a timetable. Your data stays until you ask us to remove it or a member of staff removes it, and some records such as issued invoices have to be kept for tax purposes either way.
Running a supplier review?
This page is our answer, and we will confirm anything on it in writing. If your checklist asks about something we have not covered, ask us directly. You will get a straight yes or no, including the times the answer is no.
Ask us a security question