← ShareMyPage

Trust and security

Everything a security review, a procurement team, or a curious customer needs, in one place. We keep the detail in our documentation rather than restating it here, so there is one version of every answer and it cannot drift.

Hosted in the EU. Your page content, database, and serverless compute all run in Frankfurt (eu-central-1 / fra1). Authentication, payments, and AI generation use subprocessors outside the EU, covered by the EU Standard Contractual Clauses.

We publish what is not built alongside what is. The reviewer document carries a single table of every known gap, including the controls we are most often asked for and do not yet have.

For security reviewers

Identity, tenant isolation, audience control, data residency, deletion and retention, token handling, and a single table of known gaps. Written for the person doing a vendor assessment.

Security and containment

How pages that run their own JavaScript are sandboxed, and why a published page can never reach your account.

AI and your content

What is sent to a model when you use the AI features, which models run, retention, and training.

Subprocessors

Every third party that processes data on our behalf, what each one handles, and where.

Data Processing Agreement

How we process personal data on your behalf under Article 28 GDPR, and how to execute a countersigned DPA.

Privacy Policy

What personal data we process, why, and the rights you have under the GDPR.

Terms of Use

The terms that govern your use of the service.

Report a vulnerability

Found something? Write to security@sharemypage.app. We aim to acknowledge within five working days and will not pursue researchers acting in good faith.

Questions a page does not answer? Write to security@sharemypage.app and we will answer directly rather than have you infer it.