1. Encryption and data protection
All communications with MarketingAtelier are encrypted with TLS. Passwords are hashed and are never stored in plain text. Third-party API keys (Stripe, ESP, OAuth social networks) are encrypted with AES-256-GCM in the database, using dedicated keys per use case.
- TLS encryption (1.2 minimum) on all connections.
- Passwords hashed (bcrypt for accounts, PBKDF2 for member areas of published sites), never stored in plain text.
- Stripe keys (user), ESP tokens, LinkedIn and Meta tokens: AES-256-GCM encryption in the database.
- HMAC-SHA256-signed JWTs for member sessions on published sites.
2. Infrastructure
The platform relies on three infrastructure providers, each with its own security perimeter.
- Supabase — PostgreSQL database with Row Level Security (RLS), authentication, and file storage. Hosted in Paris (AWS region eu-west-3).
- Vercel — application platform hosting, continuous deployment from Git. Functions run in Paris (cdg1 region), next to the database.
- Cloudflare Pages — hosting for sites published via WebAtelier. Global CDN network.
AI processing (Anthropic, OpenAI, Mistral, fal.ai, Replicate) and email delivery (Resend) rely on sub-processors listed in our privacy policy, some of them outside the European Union.
3. Authentication and access
- Email and password authentication (Supabase Auth).
- Secure sessions with automatic token rotation.
- Multi-user workspace (Pro and Business plans): invite members to your workspace.
- Per-account data isolation enforced on every API call, with PostgreSQL Row Level Security as a second barrier.
- Production access restricted to the technical lead.
4. Protection of user content
Content and data generated by users (templates, CRM contacts, websites, social posts) remain their property. No data is used to train third-party AI models (Anthropic, OpenAI, Replicate, fal.ai).
- Systematic HTML sanitisation (isomorphic-dompurify) before any rendering, to prevent XSS attacks.
- Validation and sanitisation of user input (Zod on critical APIs).
- Protection against SQL injection via Supabase parameterised queries.
- Security headers: HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy.
- Rate limiting on public endpoints (forms, analytics) via Upstash Redis.
5. GDPR compliance
MarketingAtelier is designed to comply with the General Data Protection Regulation. Users may exercise all of their rights at any time.
- Explicit, granular consent (by channel and message type) for CRM contacts.
- Timestamped history of consents (addition, modification, withdrawal), with source and proof.
- Right of access, rectification, erasure, and portability.
- CSV export of your contacts from the CRM; full data export on request.
- We notify the CNIL of any personal data breach within the 72 hours required by the GDPR, and inform affected individuals where the law requires.
Your data is never sold, never used to train third-party AI models, and never transferred outside the technical sub-processors listed in our privacy policy.
6. Incident detection and response
Application errors are reported automatically (Sentry) and reviewed on working days. The incident response procedure follows four phases:
- Detection — automatic reporting of server errors, and reports from users.
- Assessment — analysis of the severity and impact of the incident.
- Containment — isolation of the threat, rotation of secrets where necessary, and limitation of further propagation.
- Notification — information to affected users and, in the event of a personal data breach, to the CNIL (the French data protection authority) within the 72 hours required by the GDPR.
7. Secure development practices
- Validation and sanitisation of user input.
- Protection against SQL injection and XSS attacks.
- Automated dependency audit on every change.
- Every change is built and checked on a preview deployment before going to production.
- Mandatory code review for any change touching authentication, payment, data or the schema, and for every production release.
- Automated tests of authentication and account deletion, run before production releases.
8. Compliance
MarketingAtelier is designed to comply with the GDPR from the ground up: per-channel consent, consent history, individuals' rights, and sub-processors listed in our privacy policy.
9. Reporting a vulnerability
If you discover a security vulnerability, we ask that you report it to us responsibly. We are committed to reviewing your report, addressing the issue, and keeping you informed of the outcome.
To report a vulnerability, please use our contact form and include "Security report" in the subject line.