Loading…
Security
Collectly sits between your books and your customers. That means we see customer names, balances, payment behavior, and the dunning messages you send. Here's exactly what we do — and don't do — with that access.
All traffic is TLS 1.2+ (HSTS enabled). Data is encrypted at rest using AES-256 on managed Postgres volumes. Backups are encrypted with provider-managed KMS keys and retained for 30 days.
Role-based access via Clerk. Your team only sees the orgs they belong to. No service accounts with standing admin access. Every database query is scoped by org_id at the application layer.
Collectly runs on Vercel (compute) and managed Postgres (data). All secrets live in Vercel environment variables — never in code, never in the client bundle. No SSH access is provisioned.
Every state-changing action (dunning send, invoice update, payment mark, integration connect) writes to an immutable events table scoped by org. You can export your full audit log at any time.
What we don't do
Controls
Honest status as of today. "In progress" means we have a target date within the next two quarters.
| Control | Status |
|---|---|
| TLS 1.2+ everywhere | enforced |
| AES-256 at rest | enforced |
| Quarterly access reviews | enforced |
| Encrypted backups (30-day retention) | enforced |
| Secrets in environment variables only | enforced |
| Org-scoped queries (no cross-tenant reads) | enforced |
| SSO via Clerk (Google, Microsoft, GitHub) | available |
| SOC 2 Type II | in progress |
| GDPR + UK GDPR + CCPA compliant | enforced |
| DPA on request | available |
Incident response
We commit to notifying affected customers within 72 hours of confirming a security incident that materially impacts their data. You can reach the security team directly at security@getcollectly.app for disclosure, responsible-vulnerability reports, or to request our latest penetration-test summary.
Bug bounty: we don't have a paid program yet, but we acknowledge every responsible report within one business day and ship a fix on a negotiated timeline.
Compliance
Collectly is built for small businesses in the US, UK, EU, Australia, and Canada. Your data is processed in the region you select at signup (US or EU). We act as the data processor for your customer data; you remain the data controller. Our Data Processing Agreement is available below.