top of page

SECURITY OVERVIEW — CHECKLISTS ’R US

Last updated: June 17, 2026

Checklists ’R Us is committed to protecting the confidentiality, integrity, and availability of customer data. This Security Overview describes the administrative, technical, and physical safeguards we use to secure our website, digital products, and supporting systems.

This document is designed to give customers, partners, and auditors a clear understanding of our security posture.

 

1. Security Principles We Follow

Our security program is built on four core principles:

  • Least Privilege — Access is granted only when necessary.

  • Defense in Depth — Multiple layers of protection across systems.

  • Secure by Design — Security is integrated into product development.

  • Continuous Improvement — Regular reviews, updates, and monitoring.

For compliance details, see Data Processing Addendum.

 

2. Data Encryption

A. Encryption in Transit

All data transmitted between your device and our servers is encrypted using:

  • HTTPS

  • TLS 1.2 or higher

This protects data from interception or tampering.

B. Encryption at Rest

Stored data is encrypted using industry‑standard encryption protocols provided by our hosting platform.

 

3. Access Controls

A. Role‑Based Access

Internal access to systems is restricted based on job responsibilities.

B. Multi‑Factor Authentication (MFA)

Administrative and developer accounts require MFA to reduce unauthorized access risk.

C. Session Management

User sessions are protected with secure cookies and automatic timeout mechanisms.

For more detail, request Access Control Matrix.

 

4. Application Security

A. Secure Development Practices

We follow secure coding principles, including:

  • Input validation

  • Output encoding

  • Error‑handling best practices

  • Regular code reviews

B. Vulnerability Management

We perform:

  • Continuous monitoring

  • Regular patching

  • Dependency updates

  • Automated scanning

C. Protection Against Common Threats

Our systems include safeguards against:

  • Cross‑Site Scripting (XSS)

  • Cross‑Site Request Forgery (CSRF)

  • SQL injection

  • Brute‑force attacks

 

5. Infrastructure Security

A. Hosting Environment

Our infrastructure is hosted on secure, industry‑leading platforms with:

  • Physical data‑center security

  • Redundant power and networking

  • Fire suppression systems

  • 24/7 monitoring

B. Network Security

We use:

  • Firewalls

  • Intrusion detection and prevention

  • Rate limiting

  • Traffic filtering

 

6. Data Minimization & Retention

We collect only the data necessary to provide our Services.

Retention policies include:

  • Automatic deletion of unneeded logs

  • Secure lifecycle management

  • Customer‑initiated deletion upon request

To request deletion, use Data Deletion Request.

 

7. Backup & Recovery

A. Regular Backups

We maintain scheduled backups of critical systems and data.

B. Disaster Recovery

Our recovery plan includes:

  • Redundant infrastructure

  • Failover capabilities

  • Documented recovery procedures

C. Testing

Recovery processes are periodically tested to ensure reliability.

 

8. Monitoring & Incident Response

A. Continuous Monitoring

We monitor:

  • System performance

  • Security events

  • Unauthorized access attempts

  • Error logs

B. Incident Response Plan

In the event of a security incident, we will:

  • Investigate promptly

  • Contain and mitigate the issue

  • Notify affected customers when required

  • Document and review the incident

For breach details, see Incident Response Summary.

 

9. Third‑Party Security

A. Vendor Assessments

We evaluate third‑party providers for:

  • Security posture

  • Compliance

  • Data‑handling practices

B. Sub‑Processors

We use reputable service providers for hosting, analytics, and payment processing.

Request the list via Sub‑Processor Inquiry.

 

10. Customer Responsibilities

To maintain security, customers should:

  • Use strong passwords

  • Keep login credentials confidential

  • Enable device‑level security

  • Avoid sharing purchased content externally

  • Report suspicious activity promptly

For help, visit Security Support.

 

11. Compliance & Legal Alignment

Our security practices support compliance with:

  • GDPR

  • CCPA/CPRA

  • Standard Contractual Clauses (SCCs)

  • General U.S. privacy and security expectations

This overview is not a certification but reflects our commitment to responsible data stewardship.

 

12. Contact Information

For security questions or concerns, contact us through the Support Page.

bottom of page