Web Wizard Dev's Commitment to Data Security

When you trust us with a website or application, you're also trusting us with business data, and often your members' or customers' information. Secure web application development is how we build from day one, not a step added at the end.

Where Your Data Lives

Most of the applications we build run on two providers. Vercel serves the site and runs its server code. Supabase holds the Postgres database, user sign-in and file storage. Both run in Amazon Web Services (AWS) data centers, and AWS is responsible for their physical security.

Each Supabase project keeps its database, sign-in service and stored files in the AWS region chosen when the project is created. Our current clients' databases are in the United States, in AWS's Northern Virginia and Ohio regions. On Supabase's paid plans, each client database is backed up every day.

A region chosen at setup

We choose the database region with you at the start, based on where your users are and any rule about where your data must stay. Moving it later means a migration, so we settle it early.

Sent on to your own systems

Some organizations need records to end up on servers they control. On one client's secure document portal, uploads wait in private storage until staff approve them, then go to the client's own Azure server.

Data Privacy and Ownership

Your data belongs to you. Period.

We don't sell, analyze or reuse client data for anything beyond building, running and maintaining your application. Access goes only to the people and systems that need it to support your project, and only when they need it.

Your providers' commitments

Vercel and Supabase publish their own security and privacy terms, and they bill you directly, so we'll walk you through what they commit to.

How Your Data Is Protected

Security works best in layers. The providers secure the data centers and the platform. We build the controls inside your application.

Data Encryption

Encryption protects data on the providers' disks and on its way across the internet. Vercel and Supabase encrypt stored data with AES-256, and connections between the browser, the app and the database use HTTPS (TLS).

Access Control

Not everyone needs access to everything. Permissions are checked on the server, not just hidden in the interface.

Common safeguards

  • Staff permissions checked on the server
  • Row-level security in the database that keeps each member to their own records
  • Secret keys kept on the server, never sent to the browser

Our accounts with the hosting, database and code providers use two-factor sign-in.

Private File Storage

Forms, ID cards and medical records shouldn't travel by email. Members upload through a secure link into private, encrypted storage. Staff open files through short-lived links after a server-side permission check, then approve each one or ask for changes.

Audit Logs

On the member platforms we've built, staff actions on member data are written to an audit log that admins can read. If someone asks who changed what, there's a record to check.

Compliance and Industry Standards

We don't hold security certifications of our own, and HIPAA has no official certification for software or developers. Our part is to build the technical safeguards into your application, choose independently audited providers, and sign the agreements that make responsibilities clear.

Most of the applications we build run on Vercel and Supabase, which are both hosted on AWS. Supabase maintains SOC 2 Type II compliance for its infrastructure. That certification belongs to the provider, not to Web Wizard Dev, but it means your data sits on independently audited infrastructure. Sensitive files are kept in private, encrypted storage behind server-side access checks and short-lived links.

Vercel publishes its own SOC 2 Type 2 attestation. Card payments go through a processor's hosted checkout, such as Stripe or Square, so card numbers never touch your servers or ours. Stripe is certified as a PCI Service Provider Level 1.

For health information we sign Business Associate Agreements (BAAs), and have signed them for union and health-fund clients. Our agreements include mutual confidentiality, and we're glad to sign your NDA before a project starts.

HIPAA also expects a BAA with each vendor that stores health data, such as the hosting or database provider, so we plan for those agreements during discovery.

Accessibility

We design and build to WCAG 2.2 Level AA, the current version of the Web Content Accessibility Guidelines. It includes WCAG 2.1 AA, the level the U.S. Department of Justice requires of state and local government websites, and the level HHS names for organizations that receive its funding.

Before launch we run automated Lighthouse checks across the site's main pages, and we test the home page and one or two other key pages by hand, using only a keyboard and zoomed in. Screen reader testing is available when your project needs it. On a union benefits fund's site we rebuilt, all 11 audited pages score 100 for Lighthouse accessibility.

An accessibility problem in our work is a bug, so it's covered by the free fixes after launch. We can also write an accessibility statement for your site. A few parts sit outside our control: a payment provider's checkout page, Google's reCAPTCHA, PDFs and videos you supply, and content your team adds after launch. We tell you which ones apply to your project.

Want to verify requirements?

If you're in a regulated industry, we can help you understand what standards matter and what controls are appropriate for your application.

Ongoing Security Work

Security is not a one-time setup. Code changes and new attacks appear, so the checking continues after launch.

Security Audits

We audit the code we build: sign-in and access checks, database access rules, leaked secrets, security headers, and known vulnerabilities in the packages an app depends on. The benefits fund's portal has been through three audit rounds.

Tests That Check Access

On the member platforms we've built, automated tests check who can read and change what in the database. They run as the code changes, so a change that loosens access gets caught.

Platform Protection

Vercel automatically mitigates denial-of-service (DDoS) attacks on every plan. Its firewall also lets us add rules that block or rate-limit abusive traffic when a site attracts it.

Updates and Uptime

On a support plan, we apply security updates to your app's packages, and we watch uptime, errors and database health in Vercel's and Supabase's dashboards.

Your Control and Transparency

You keep control of your data. Your domain is registered in your name, the providers bill you directly for hosting and the database, and a project on our accounts moves to yours whenever you ask. We explain your options for storage, access and encryption, and set them up correctly.

If questions come up, you'll get clear explanations, not vague assurances.

We respect business constraints

Security should fit the real world: live users, timelines, budgets, and compliance needs. We aim for practical improvements with measurable outcomes.

We document what matters

For production systems, we can document access models, deployment environments and operational procedures, so you don't depend on one person's memory.

A Security-First Foundation

Our data security practices come down to a few habits: build on independently audited providers, keep sensitive data private by default, check access on the server, and tell you plainly what is and isn't covered. No method of storing or sending data is 100% secure, and we won't claim otherwise.

Your data matters. We treat it that way.

wizard hat

Have Security Questions About Your Website or App?

If you're handling customer data, payments or regulated information, security details matter. We'll answer your questions clearly, explain your options and recommend practical controls that fit your product. We reply within 1 business day.

Provider security pages: Vercel, Supabase, and AWS compliance (the data centers under both).