Trust & Security
Here's exactly how your data is protected.
No vague promises. Real infrastructure, real monitoring, and real control over your own data, explained plainly.
Infrastructure
DigitalOcean, our hosting foundation
SOC 2 Type II, SOC 3 Type II, and GDPR certified, with Cloud Security Alliance STAR Level 1 status, for their own infrastructure. Cloud Firewalls restrict traffic to only what's explicitly permitted. Our backups are stored encrypted at rest in DigitalOcean Spaces.
See DigitalOcean's trust pageCloudflare, in front of every request
DDoS mitigation is always-on at Cloudflare's network edge, before traffic ever reaches our servers. Cloudflare also terminates HTTPS/TLS encryption for every visitor to the site.
See CloudflareThose certifications belong to DigitalOcean's and Cloudflare's own infrastructure, not to SeenOnMain itself. On top of that foundation, SeenOnMain adds its own layer: a dedicated, isolated server for every client, never shared with any other business, plus our own encrypted backup schedule and monitoring, both described below.
Monitoring
We check on your site continuously, not just when something breaks and you tell us. One automated check runs every 5 minutes watching overall platform health, and another runs every 20 minutes checking that every individual client site is actually up and responding, with an AI-assisted first look at what's wrong if one isn't, so we usually know before you do.
Compliance
SMS numbers are registered with US carriers (A2P 10DLC / toll-free verification) before sending business text messages, and a STOP reply is honored immediately and permanently, across the platform.
Every email includes a working unsubscribe link, honored the moment it's used, in line with CAN-SPAM.
The missed-call-to-text reply is a single, one-time message, never a recurring campaign, never sent before 8am or after 8pm local time regardless of any business's own settings, and a STOP reply from that number is honored instantly and permanently for that business, enforced both in our own code and at the carrier level via Twilio's Advanced Opt-Out.
Consent to that missed-call reply is verbal and affirmative, captured at the start of the call itself, before the business owner's phone even starts ringing. Every caller hears exactly this, spoken aloud: "Thanks for calling [Business Name]. If we can't answer, we can text you back so you're not left waiting. Press 1 to allow that text. Message and data rates may apply if you do. Connecting you now." Only pressing 1 sets consent to send that text; not pressing anything still connects the call normally, it just means no text follows if the call goes unanswered.
When a business owner replies to a customer from their business line, every message is typed by a real person, never generated or sent by AI, and the same STOP check runs before every send, so an opted-out number can never be texted again regardless of who's doing the typing.
Your data, your control
Full data export
Export your leads, quotes, customers, and reports whenever you want, from your account settings, including for 28 days after you cancel.
Account deletion
You can delete your account and its data, it isn't held hostage to keep you subscribed.
Full message log
Every email and text sent on your behalf is logged and visible to you, not a black box.
If you cancel
You keep read-only access for 28 days: you can sign in, see everything, and export your leads, quotes and customers. Sending and publishing stop immediately, so nothing goes out to your customers in your name after you've left. At the end of the 28 days your server and its data are removed. If you'd rather it was gone sooner, delete the account and it goes then.
Account security
Two-factor authentication is available on every account. New accounts require email verification, and password resets go through a secure, time-limited link, never sent in plain text back to you.
Who else touches your data
We don't sell or share your data, but a few companies process parts of it so the product can work. These are all of them:
- Anthropic (Claude) โ writes the follow-up emails and shortens a long customer message into the summary you see in your text alert. That means a lead's name and the text they typed are sent to Anthropic. Their commercial terms say it plainly: "Anthropic may not train models on Customer Content from Services." Read their terms. No AI ever talks to your customer live.
- Twilio โ carries the calls and texts, and is who your business number is registered with.
- Resend โ delivers the emails, so it handles the address and the message going to your lead.
- DigitalOcean โ runs your server and stores the encrypted backups.
- Cloudflare โ sits in front of every request.
- Stripe โ takes the payment. We never see or store your card number.
What we don't do
- โSell or share your data with third parties for marketing
- โMessage your leads or customers without consent, or ignore a STOP/unsubscribe request
- โRun AI conversations with your leads or customers on your behalf, see the Glossary for what our AI assistant actually does
- โLock your data in, you can export or delete it at any time
Questions we didn't answer here?
Reach out directly, or check the Knowledge Base for more on how everything works.