BETA

Security and data handling

This page describes what HelpCCMS makes public, what remains private, where data is processed and how you can export it.

Public and private content

Published content. Published topics are publicly readable through the delivery API. No authentication is required, and CORS is open so applications can request published content directly from a browser.

Anyone who knows a collection id can request published content from that collection. Do not publish confidential information.

Drafts. Draft content is not available through the public delivery API. When a topic is unpublished, it stops being available through delivery after the cache window expires.

Account data. The editor, collections, drafts, account details and billing information require authentication. Application pages are excluded from search-engine indexing and are protected against framing with X-Frame-Options: DENY and Content-Security-Policy: frame-ancestors 'none'.

Collection ids

A collection id identifies the collection to read from. It is not a credential.

Collection ids appear in delivery URLs and may therefore be visible in browser network requests. Knowing a collection id does not provide write access.

Data storage and processing

DataProviderNotes
Content, drafts and published versionsSupabase, EU region
Account and login dataSupabase, EU regionPasswords are handled by the authentication provider
Payment detailsStripeCard data does not pass through HelpCCMS systems
Application hostingVercel, EU region

See subprocessors for the current provider list and transfer basis, and the data processing agreement for the terms that apply to customer content and personal data.

Transport and caching

HelpCCMS uses HTTPS. Published content can be cached at the edge for up to five minutes.

Responses include an ETag. Clients can send it as If-None-Match and receive 304 Not Modified when the published snapshot has not changed.

Export

You can export your HelpCCMS content as structured JSON from your account. The export contains:

Published content also remains available through the delivery API while the account is active.

Reporting a security issue

Email support@helpccms.com. If the issue may expose content or data that should not be public, state that in the subject or the first line.

Certifications

HelpCCMS currently makes no certification claims. This page describes the controls and behaviour currently implemented in the product.

← HelpCCMS