Security

Your work and your clients, protected

You trust Tiggybooks with your business and your clients’ details. We take that seriously. Here is exactly how we keep that information safe, in plain language.

Protected by default

Security that is on from day one, not an upsell.

  • HTTPS everywhere, enforced
  • Encrypted at rest
  • Payments via Stripe, no card numbers stored
  • Every account walled off from the rest
  • Files locked until paid and unlocked by you

How we protect your information

Layered protection across the whole platform, from the connection in your browser to the files on disk.

Encrypted in transit

Every connection to Tiggybooks runs over HTTPS with modern TLS, now enforced with HSTS so browsers refuse to load the site over an insecure connection.

Encrypted at rest

Your records and your files are stored encrypted at rest in our managed database and file storage. Data sitting on disk is never in the clear.

We never see card numbers

Payments run on Stripe, a PCI-DSS Level 1 provider. Card details go straight to Stripe. We only keep a secure token plus the brand, last four digits, and expiry so you know which card is on file.

Strict account isolation

Every business lives in its own walled-off workspace. Each request is checked against your account, so one customer can never read another's clients, files, or payments.

Locked file delivery

Client downloads need a unique, unguessable link, and for paid delivery a completed payment, before a single file is released. Your work stays private until you say so.

Secure sign-in

Passwords are hashed, never stored in plain text. Sessions are signed with a server-only secret, and password resets use single-use links that expire within the hour.

Abuse and spam protection

Rate limiting and bot checks guard public forms, sign-up, and payment endpoints, so the platform stays available and your inbox stays clean.

Hardened against common attacks

Input is sanitized against cross-site scripting, database access is fully parameterized against SQL injection, payment webhooks are signature-verified, and every page carries hardened security headers.

Your data stays yours

Export your information whenever you like, with no lock-in. We do not sell your data, and we only keep what running your business actually needs.

Built on trusted infrastructure

We run on the same providers that power critical systems for thousands of companies, so your data sits on hardened, well-managed foundations.

Stripe

Payments, PCI-DSS Level 1

Vercel

Application hosting, TLS

Neon Postgres

Database, encrypted at rest

Cloudflare R2

File storage, encrypted at rest

Our approach

Your data, your control

It is your information. You can take it with you or remove it entirely, at any time, no email required.

Export anytime

Download everything we hold for your account as a single file, straight from Settings.

Delete on demand

Permanently erase your account and all of its data whenever you want. Any active subscription is canceled.

Correct anything

Your details are always editable in the app, so your records stay accurate and current.

Found something? Tell us.

If you believe you have found a security issue, please email us. We read every report, respond quickly, and we will keep you posted on the fix. Responsible disclosure helps keep every creative on Tiggybooks safe.

hello@tiggybooks.com

Run your business on a platform that protects it

Join the early access waitlist. Security is built in from the start, not bolted on later.