Security & reliability
Where your things live, and who can reach them.
Last updated August 2, 2026 · written in plain words on purpose.
The short version. Your website runs on Cloudflare's network. Your customers' enquiries live in a database only we can reach, and they're emailed to you the moment they arrive. Card numbers never touch us. Nothing you give us is sold, shared, or used to train anything.
Where your website runs
- Cloudflare. Every site we build is served from Cloudflare's global network — the same infrastructure behind a large share of the web. There is no server of ours sitting in a cupboard to fall over.
- HTTPS on everything, always. The certificate is issued and renewed automatically. You'll never get the "not secure" warning, and you'll never have to remember a renewal date.
- Static files. Your site is plain HTML, CSS and images — no WordPress, no plugins, no database powering the public pages. That matters for security: the most common way small-business sites get hacked is an out-of-date plugin, and there isn't one to go out of date.
Your customers' details
- Where enquiries go. When someone fills in the form on your site, it's written to a Cloudflare D1 database and emailed straight to you. Reply to that email and you're talking to your customer, not to us.
- Who can see it. Us, and you. No third-party marketing tools, no data brokers, no advertising pixels. We do not sell or share your customer list, and we don't use your customers' details to train AI models.
- Encryption. Everything travels over HTTPS, and Cloudflare encrypts the databases at rest.
- Deletion. Ask and we delete your leads, your uploads, and your account. It's yours — you shouldn't have to argue for it.
Money never routes through us
- Your customers pay you. The payment buttons and pay-links on your site and in your tools point at your own Stripe, Square, PayPal or Venmo account. The money lands with you.
- We never see a card number. Our own checkout is Stripe-hosted, so your card details don't touch our systems either.
- Your texting account is yours. Workflow-tool clients own their Twilio account, their phone number, and their carrier registration outright. If you leave, they leave with you — we can't hold your number hostage because we never held it.
Accounts and access
- Passwords are hashed with PBKDF2-SHA256 at 100,000 iterations and a per-account salt. We can't read yours, so we can never email it back to you — we can only send a reset link.
- Sessions use HttpOnly, Secure cookies. Resetting your password signs you out everywhere else.
- Brute-force limits cap repeated sign-in attempts, and a bot check sits in front of sign-up and sign-in.
Backups, and what we watch
- Your site's source is in version control and exported weekly. If a page were ever damaged, restoring it is a matter of minutes, not a rebuild.
- Automated checks run through the day against the live site, the account system, and the lead pipeline. If one fails, it pages a phone, not an inbox nobody reads.
- Honest limit: we don't publish an uptime percentage, because a number we measured ourselves for a few months wouldn't mean much. What we can tell you is what our checks watch and how fast we're told — above and below.
When something breaks
- Site down, form not sending, tool gone quiet: that's an emergency on our end. Reply to any email or send it from your account page and it reaches a phone immediately. We aim to have a person on it within two hours between 8am and 8pm Mountain time, and to tell you what's happening even when the fix takes longer.
- Normal changes — hours, prices, a new photo, wording in a tool — get done the same business day. Most take minutes.
- We tell you when we get it wrong. If we break something on your site, you'll hear it from us first, with what happened and what we changed so it doesn't repeat.
What we're not
We're a small operation, and there are things we'd rather say plainly than have you discover later. We're not SOC 2 certified. We don't offer a signed uptime SLA with credits. We're not built for storing medical records, card data, or anything else with its own compliance regime — if your business needs HIPAA or PCI handling, we're the wrong shape and we'd tell you that before taking your money.
Found a problem?
If you spot a security issue, email support@plainsmith.co with what you found. We'll confirm we got it, fix what needs fixing, and tell you what we did. No lawyers, no runaround.