The actual building blocks.
No marketing lists of certifications we don't have. Here's where your account, your content and your payments actually live — and what we do to keep them safe.
Real vendors, real controls.
We ride on top of vendors who've already done the compliance work at scale. Where their posture applies (auth, payments, data at rest), it applies to you.
Authentication — Clerk
Sign-in, session management, MFA and email verification are handled by Clerk. Passwords never touch our servers; we store a Clerk user ID and the profile fields we ask for. Clerk holds SOC 2 Type II and is HIPAA-eligible.
Application data — Neon Postgres
Projects, credit ledgers, brand kits and audit trails live in a managed Postgres cluster on Neon. Encrypted at rest, encrypted in transit, with point-in-time recovery in case of accidental deletion or corruption.
Media & assets — S3
Product images, rendered MP4s and uploaded custom-avatar footage are stored in Amazon S3 with server-side encryption at rest. Access to buckets is scoped to the account that owns the content — signed short-lived URLs, no public listings.
Transport — TLS everywhere
Every request between your browser, the app and our upstream vendors is over TLS 1.2+. HSTS is on in production so browsers refuse to downgrade.
Payments — hosted checkout
Card details never touch our infrastructure — Paytree hosts the checkout on Stripe's PCI DSS Level 1 infrastructure; we receive a payment status and reference, never a card number.
Backups & audit
Point-in-time recovery on the primary database. Structural changes and sensitive operations write to an audit log we can inspect. If something goes sideways, we can reconstruct what happened.
What we don't claim.
We're a pre-launch team. Some things a mature security page would claim, we can't honestly claim yet. Here's where we are today.
- We don't have our own SOC 2 report yet.
We're a small, pre-launch team and haven't gone through a formal audit. If your org needs one, we can share the SOC 2 reports of our sub-processors (Clerk, Neon, Stripe, AWS, Vercel) — that covers where your data actually lives.
- No public bug bounty program yet.
We handle reports directly for now (see below). We'll open a formal program once the volume justifies it.
- No 24/7 on-call.
We monitor uptime and get paged on outages, but we're a small team — expect fast fixes during business hours and best-effort response outside them.
Found something? Tell us.
Email privacy@ugcabc.com with details and a proof-of-concept. Please give us reasonable time to investigate and patch before any public disclosure. We won't take legal action against good-faith security research that stays within our scope, avoids third-party data, and doesn't disrupt the service for other users.