Trust and data handling
Last updated: July 10, 2026
Use this page before procurement review or when answering a buyer security question. It summarizes what CertCue does, what it does not do, and which controls are buyer-owned in the app.
Workflow tool only
CertCue helps organize vendor paperwork, renewal ownership, follow-ups, imports, exports, and workspace handoff. It is not an insurer, broker, attorney, compliance verifier, or document interpretation service.
Safe support and import habits
Use the in-app import and upload paths for business records. Do not send card numbers, bank details, passwords, private magic links, API keys, or sensitive files through support messages or email.
Storage modes
Browser sample workspaces store data locally on the buyer's device. Signed-in workspaces use organization-scoped Supabase storage when Supabase is connected and the buyer creates a cloud workspace.
Buyer controls
Settings export, backup, restore, and clear-data controls let buyers keep, move, or remove workspace records without waiting on support. Settings can also copy support and buyer trust packets for review.
Security boundaries
Server-only service-role, Stripe, reminder, and analytics secrets stay server-side. Supabase row-level security and Edge Functions enforce organization boundaries, and CSV exports resist spreadsheet formula injection.
Current launch status
Support is available through support@cert-cue.com. Team and Pro use Stripe-hosted Checkout and the Stripe customer portal; card details never pass through CertCue support. No guaranteed response-time SLA is included unless agreed separately.
Review links
Read the current privacy policy, terms of service, support page, and paid setup page. Buyers can also open Settings for exports, backups, workspace restore, clear-data controls, support packets, and the in-app buyer trust packet.