Security & Data Handling

How OrgPhoto protects your roster and employee photos.
The short version. OrgPhoto runs entirely on Cloudflare's serverless platform. Your files are encrypted in transit and at rest, isolated per organization, and — if you choose — deleted automatically after your PDF is delivered. We ask for the minimum data needed to build a directory and nothing more.

Architecture

OrgPhoto is delivered by a Cloudflare Worker with data stored in Cloudflare D1 (accounts and job records) and Cloudflare R2 (uploaded files and generated PDFs). There is no traditional origin server: no virtual machine, no SSH, no open network ports, and nothing for us to leave unpatched. Every request passes through Cloudflare's WAF and DDoS protection at the edge.

Encryption

Tenant isolation & access

Data retention — your choice, every time

For each directory you generate, you choose how we handle the data:

To delete a saved directory today, email us and we will remove it from storage and confirm. Self-service deletion from your dashboard is in development; we would rather tell you exactly how this works now than describe a button that does not exist yet.

Data minimization

The required roster format asks only for employee name, title, and photo filename. We do not request or store Social Security numbers, dates of birth, compensation, addresses, or other sensitive personnel data. Please do not include such fields in uploads.

Credentials

Upload safety

Uploaded rosters must match the required template, and photos are validated by type and size and confirmed to be real image files before processing. Files that do not match the format are rejected.

Subprocessors

OrgPhoto uses Cloudflare (Workers, D1, R2) for hosting, storage, and edge security. Generation runs on infrastructure controlled by the operator. We do not sell your data or share it with advertisers.

What we do not claim

We want to be precise: OrgPhoto is not currently SOC 2 or ISO 27001 certified and has not undergone an independent third-party penetration test. If your organization requires formal attestation or a pen-test report, contact us and we will scope that with you rather than imply certifications we do not hold.

Incident response

If we become aware of unauthorized access to customer data, we will investigate, contain the issue, and notify affected organizations promptly with the information available.

Questions about security? Contact us before you upload — we're happy to walk your security team through this.