This page describes the website you are reading and the intake it posts to. Each statement below is something the code does today.
Where your information goes
When you send the contact form or the revenue calculator, your browser posts it to an intake function we run. That function writes one record to our managed Postgres database and then creates a contact and an opportunity in GoHighLevel, the platform our team works in. A copy of the same submission is also emailed to us through FormSubmit, so the team sees it. If the intake function cannot be reached, that email is how the submission arrives, so an inquiry is not silently lost. The page tells you which of those two happened.
The record holds what you typed, the page you were on, the page you arrived on, the referring site, any campaign tags in the link you followed, and your browser's user agent string.
What protects it
In transit. The site, the intake function, the database and the CRM are reached over HTTPS. Nothing is sent to us over a plain connection.
Your address is not kept. The intake function hashes your IP address with a secret held on the server before anything is written, and stores only the hash. The raw address is never saved and the secret never leaves the server.
Browsers cannot read or write the tables. Row level security is on for the lead, booking, calculator and event tables. The permission that once let a browser insert a lead directly was revoked, so only the intake function's server-side key can write. Reading a lead requires a signed-in account that appears in our administrators table. There is no public read path.
The intake function checks the request. It accepts posts from a fixed list of our own origins, rate limits repeat submissions from the same hashed address, strips control characters, truncates every field to a maximum length, and uses a per-submission key so a retry cannot create a second record or a duplicate CRM opportunity.
Credentials are server-side. The GoHighLevel token, the database service key and the address-hashing secret are environment variables on the intake function. They are not in the browser bundle and not in this website's source. The two values that do appear in the source, the project address and its publishable key, are the ones designed to be public and are useless without the policies above.
We never see a card. Plan buttons open an inquiry. The website does not collect card details. If you proceed, payment arrangements are confirmed with the team before you commit.
Third-party code waits. The chat widget and the booking calendar are HighLevel's, and neither runs until you allow it. The cookie policy lists exactly what each one stores.
What we do not claim
We hold no third-party security certification. We are not SOC 2 audited and not ISO 27001 certified, and we do not say otherwise anywhere. HIPAA has no certification program at all; Business Associate Agreements are available for qualifying healthcare clients, and a platform safeguard is not by itself a compliant implementation. See Trust and security for the full wording.
We have not published an independent penetration test. We publish no uptime commitment. We do not offer a paid bug bounty.
Response-header hardening for this marketing site is not finished, and we would rather write that down than let its absence read as a guarantee.
Not yet published
Pending The hosting region of our database, and the retention window we apply to the lead records described above. Both exist; neither is published here yet, because publishing a number we have not confirmed is worse than saying we owe you one. Ask and we will answer in writing.
Reporting a problem
If you believe you have found a vulnerability in this site, in our intake function, or in anything else we run, email chleb@chleb.ai with the subject line "Security". Please include what you found, the steps to reproduce it, and how we can reach you. A person reads every one of these.
Please do not access, change or delete information belonging to anyone else while testing, and please do not run anything that would degrade the service for other people. Use your own test submissions.
Contact
Chleb Holdings LLC (DBA Chleb AI) · Tampa, FL, United States