Legal
Security
Last updated: October 9, 2026
Tellr holds your brand material, drafts, published work and the credentials you connect. This page describes how that is protected, in plain terms. Found a problem? Write to team@usetellr.com.
Encryption
- In transit. Every connection to Tellr is HTTPS. Browsers are told never to use plain HTTP for usetellr.com or any of its subdomains (HSTS).
- At rest. The database and file storage are encrypted at rest by our database provider.
- Credentials you connect. Google and Gmail tokens and WordPress application passwords are encrypted by Tellr (AES-256-GCM) before they are stored, with a key kept outside the database. Credentials for connected AI assistants are stored only as a one-way hash. None of these can be read back from the database alone.
Your workspace is yours alone
- Isolation in the database. Every client workspace is separated by row-level security in PostgreSQL: the database itself refuses to return or change another workspace's rows, whatever the application asks for. Read-only roles are read-only at the database too.
- Checked on every request. Each page and API call also verifies, on the server, that you belong to the workspace you are opening.
- Tested on every change. An automated suite creates two workspaces and tries to read and write across them, as a signed-in user and as an anonymous one. It runs against a fresh copy of the database on every code change.
Signing in
You sign in with Google, with a single-use link sent to your email, or with a password. Sign-in, password-reset and link requests are rate-limited. Sessions are signed tokens that expire and are refreshed automatically.
Payments
Payments are handled by our payment processor, which is certified to PCI DSS Level 1. Tellr never sees or stores your card number; it goes straight from your browser to the processor.
Infrastructure
- Where it runs. The application and the database run in Frankfurt (EU), with hosting and database providers whose controls are independently audited under SOC 2 Type II.
Audit logging
Changes to accounts, workspace membership and roles, workspace settings and connected credentials are recorded in an append-only log: what changed, when, and by whom. Secrets are never written to it, and nobody — including Tellr — can edit or delete its entries.
How we build
- Every change is scanned for leaked secrets, vulnerable dependencies and insecure code patterns before it can ship, and the live site is scanned weekly.
- Inputs to the API are validated, expensive operations are rate-limited, and the browser is sent strict security headers.
- Error reports are stripped of email addresses, tokens and cookies before they leave our servers.
- Access to production systems is limited to the people who run the service.
Reporting a vulnerability
If you think you have found a security issue, email team@usetellr.com with enough detail to reproduce it. Please don't access data that isn't yours, and give us a reasonable chance to fix it before telling anyone else. Our security.txt has the same details.