Skip to content

← Features

Security

Your site, your data, and your Admin permissions are protected from the start.

Secure from the platform to your Admin

Your site holds what your users entrusts with you: their email addresses, their messages, and their orders. Note to mention the work of your own that you haven't published yet. Cardel protects all of it from the moment you create your site. There's no security plugin to install, no server to patch, and no setting to remember. Cardel runs the platform, securely. You run your site, stress free.

Blog: How Website Speed, Security, and Accessibility Build Trust


A secure platform

Every Cardel site is served over HTTPS, whether it lives on a Cardel address or your own domain. Before Cardel shows your site on your own domain, it checks that you own that domain, so nobody else can point it somewhere and claim it. Your pages can't be loaded inside someone else's site to trick visitors into clicking something they didn't mean to.

Cardel keeps a fixed list of security rules, and every update is tested against them before it ships. If a change would break one, it doesn't go out.


A secure site

Drafts stay private until you publish them. Visitors only see what you've published, and a hidden site stays hidden and out of search while you keep working on it.

Sign-ins, contact forms, newsletter sign-ups, comments, likes, chat, and checkout all slow down any person, or bot, who tries too many times too fast. Spam and password guessing don't make it far on Cardel, and real visitors never notice. Uploaded images are checked by what's actually inside the file, and the writing in your posts and emails is cleaned of anything that could run code on a reader's screen.


Permissions you control

You decide who helps run your site and what each person can open. Every Admin signs in with their own account, so nobody needs to share passwords. Choose the areas each admin on your team can use, like Posts, Messaging Center, Audience, or Orders, and change or remove their access to specific areas whenever you need to. Users, Payments, and the AI Assistant tab stay with the Workspace Owner.

Access is checked every time someone opens a page or saves a change, not just hidden from a menu. Being an Admin on another Cardel site doesn't get anyone into yours, and the AI Assistant works within the same permissions as the person using it.

Blog:


Your data stays yours

Your subscribers, posts, messages, orders, and brand files belong to your site and nobody else's. Cardel identifies the site each user is on, then loads only that site's information. The database holds the same line on its own, so one site's data on Cardel can't appear on another, even by mistake.

Passwords are never stored as plain text, they are always securely hashed, and changing your password signs out every other browser using your account.

Card payments are processed through Stripe, so card numbers never touch Cardel.

People booking time with you only see when you're free, not actual events on your calendar.

New newsletter subscribers confirm by email before they're added, and when you import a list, you confirm those people agreed to hear from you.

Even Cardel's own team is treated as a visitor on your site. If a Cardel operator needs to help assist you on your site, they have to turn that access on deliberately and confirm they have a reason and approval. That access closes on its own after eight hours, and every time is recorded for auditing.


A few things worth knowing

Cardel protects the platform running your site. You decide who gets access and what you ask people to share. Give each person access only to the areas their work needs, and remove their access when the work ends. Inviting Admins and choosing their areas come with Pro and Studio plans. On Starter, it's just you.

Logging out signs you out of every Cardel site at once.

Forge your community

Your work deserves a home of its own.

Bring your audience together, and start growing your community with Cardel.