SECURITY OVERVIEW — CHECKLISTS ’R US
Last updated: June 17, 2026
Checklists ’R Us is committed to protecting the confidentiality, integrity, and availability of customer data. This Security Overview describes the administrative, technical, and physical safeguards we use to secure our website, digital products, and supporting systems.
This document is designed to give customers, partners, and auditors a clear understanding of our security posture.
1. Security Principles We Follow
Our security program is built on four core principles:
-
Least Privilege — Access is granted only when necessary.
-
Defense in Depth — Multiple layers of protection across systems.
-
Secure by Design — Security is integrated into product development.
-
Continuous Improvement — Regular reviews, updates, and monitoring.
For compliance details, see Data Processing Addendum.
2. Data Encryption
A. Encryption in Transit
All data transmitted between your device and our servers is encrypted using:
-
HTTPS
-
TLS 1.2 or higher
This protects data from interception or tampering.
B. Encryption at Rest
Stored data is encrypted using industry‑standard encryption protocols provided by our hosting platform.
3. Access Controls
A. Role‑Based Access
Internal access to systems is restricted based on job responsibilities.
B. Multi‑Factor Authentication (MFA)
Administrative and developer accounts require MFA to reduce unauthorized access risk.
C. Session Management
User sessions are protected with secure cookies and automatic timeout mechanisms.
For more detail, request Access Control Matrix.
4. Application Security
A. Secure Development Practices
We follow secure coding principles, including:
-
Input validation
-
Output encoding
-
Error‑handling best practices
-
Regular code reviews
B. Vulnerability Management
We perform:
-
Continuous monitoring
-
Regular patching
-
Dependency updates
-
Automated scanning
C. Protection Against Common Threats
Our systems include safeguards against:
-
Cross‑Site Scripting (XSS)
-
Cross‑Site Request Forgery (CSRF)
-
SQL injection
-
Brute‑force attacks
5. Infrastructure Security
A. Hosting Environment
Our infrastructure is hosted on secure, industry‑leading platforms with:
-
Physical data‑center security
-
Redundant power and networking
-
Fire suppression systems
-
24/7 monitoring
B. Network Security
We use:
-
Firewalls
-
Intrusion detection and prevention
-
Rate limiting
-
Traffic filtering
6. Data Minimization & Retention
We collect only the data necessary to provide our Services.
Retention policies include:
-
Automatic deletion of unneeded logs
-
Secure lifecycle management
-
Customer‑initiated deletion upon request
To request deletion, use Data Deletion Request.
7. Backup & Recovery
A. Regular Backups
We maintain scheduled backups of critical systems and data.
B. Disaster Recovery
Our recovery plan includes:
-
Redundant infrastructure
-
Failover capabilities
-
Documented recovery procedures
C. Testing
Recovery processes are periodically tested to ensure reliability.
8. Monitoring & Incident Response
A. Continuous Monitoring
We monitor:
-
System performance
-
Security events
-
Unauthorized access attempts
-
Error logs
B. Incident Response Plan
In the event of a security incident, we will:
-
Investigate promptly
-
Contain and mitigate the issue
-
Notify affected customers when required
-
Document and review the incident
For breach details, see Incident Response Summary.
9. Third‑Party Security
A. Vendor Assessments
We evaluate third‑party providers for:
-
Security posture
-
Compliance
-
Data‑handling practices
B. Sub‑Processors
We use reputable service providers for hosting, analytics, and payment processing.
Request the list via Sub‑Processor Inquiry.
10. Customer Responsibilities
To maintain security, customers should:
-
Use strong passwords
-
Keep login credentials confidential
-
Enable device‑level security
-
Avoid sharing purchased content externally
-
Report suspicious activity promptly
For help, visit Security Support.
11. Compliance & Legal Alignment
Our security practices support compliance with:
-
GDPR
-
CCPA/CPRA
-
Standard Contractual Clauses (SCCs)
-
General U.S. privacy and security expectations
This overview is not a certification but reflects our commitment to responsible data stewardship.
12. Contact Information
For security questions or concerns, contact us through the Support Page.
