Skip to main content
Legal

Security

Last Updated: October 1, 2026

1. Payments

  • All payments go through Stripe Checkout, a payment page hosted by Stripe. You enter your card details on Stripe's site, not ours.
  • Your full card number, expiry date and security code never reach our servers, and we never store them. We receive only the payment status, the amount and a payment reference.
  • Stripe is certified as a PCI DSS Level 1 Service Provider, the highest level of certification in the payment card industry, and supports 3D Secure authentication where your bank requires it.

2. Your Account

  • Passwords are stored only as salted hashes, never in readable form. Nobody at SaaSCity can see your password.
  • Your sign-in session is kept in a cookie on saascity.io, sent only over HTTPS, and ends when you sign out.
  • Sign-up, sign-in and password reset are protected against bots by Cloudflare Turnstile and by rate limits.
  • You can delete your account yourself from your account settings (see the Privacy Policy).

3. The Site and Your Data

  • Encryption in transit: every page and API is served only over HTTPS (TLS), with HTTP Strict Transport Security telling browsers never to connect without it.
  • Network protection: traffic passes through Cloudflare, which filters attacks, abusive traffic and bots before they reach our server.
  • Browser protections: a Content Security Policy and other security headers limit what scripts can run and stop the site from being framed by other sites.
  • Access control: the database enforces row-level security, so each account can read and change only its own private data. Administrative access is limited to the operator.
  • Hosting: the Service and its database run on a server in Germany, in the European Union. Automated database backups are copied off the server.
  • Downloads: purchased files are kept private and delivered through short-lived download links.
  • Data minimization: our own analytics stores IP addresses only as salted one-way hashes, API keys are stored only as hashes, and error reports are configured not to collect your name, email address, cookies or form contents.
  • Uploads: images you upload are checked automatically before they are published.

No system is perfectly secure. If a breach affects your personal data and puts your rights at risk, we will notify the data protection authority and, where the law requires, you, as the Privacy Policy describes.

4. Reporting a Vulnerability

If you find a security problem in saascity.io, please tell us at [email protected]with the subject line "Security". Include what you found, the steps to reproduce it, and its impact as you understand it. We acknowledge reports within 5 business days and keep you updated until the problem is fixed.

We will not take legal action against research done in good faith that follows these rules:

  • Test only against your own account and data. Do not access, change or delete other people's data; if you reach any by accident, stop and tell us.
  • Do not degrade the Service: no denial-of-service tests, spam, automated scanning at high volume, or social engineering of users or of us.
  • Give us reasonable time to fix the problem before you disclose it publicly.

We do not run a paid bug bounty program, but we are glad to credit you once the problem is fixed if you would like. Our security.txt file has the same contact details in machine-readable form.