Security and compliance at Famewall

Famewall helps businesses collect, manage, and display testimonials. This page explains the security controls we currently rely on, what we publicly document today, and where to contact us if you need more detail.

For legal terms, see our Privacy Policy and Terms of Service.

What this page covers

This is a practical overview for prospects and customers.

Who to contact

Security questions, privacy requests, and procurement follow-ups can be sent to contact@famewall.io.

Core safeguards

Famewall uses a mix of application-layer protections, managed infrastructure, and operational tooling to protect customer accounts and testimonial data.

Account protection

Authenticated dashboard access uses signed access tokens, sensitive requests are protected, access tokens are short-lived, and blocked tokens can be invalidated to reduce session risk. Browser access is restricted to approved origins where applicable.

Application safeguards

Requests are validated before processing, input sanitization is used to reduce malformed or unsafe input, and Famewall uses HTTPS for production traffic while avoiding broad storage credentials directly in the browser.

File and media handling

Uploaded testimonial media may be stored and delivered through AWS for managed cloud storage and Mux for video processing and hosting. Customers can manage or remove testimonials and media from the product, and privacy requests can be sent to the team.

Operational tooling

Payments are processed through Stripe. Famewall also uses product analytics and support tooling to improve the product, measure usage, and respond to customer questions. Public pages, widgets, and collection flows may collect view and engagement analytics so customers can understand testimonial performance.

Public subprocessor list

The list below reflects named third-party services visible in the current Famewall codebases for the product, support workflows, and public website. Some services apply only to selected pages or features rather than every customer.

Customer-configured destinations such as webhooks, Zapier, Make, and other external apps connected by a customer are not listed here because they are enabled case by case.

Amazon Web Services (AWS)

AWS is used for core infrastructure, file storage, presigned uploads, and serverless processing that support Famewall product workflows. Place of subprocessing: United States.

Stripe

Stripe is used for subscription billing and payment processing for Famewall customers. Place of subprocessing: United States and Ireland.

Google Authentication

Google Authentication is used to support Google sign-in for Famewall accounts. Place of subprocessing: United States.

Twitter Authentication

Twitter Authentication is optional and is used when a user connects their Twitter account to import testimonials or related content from Twitter. Place of subprocessing: United States.

Mux

Mux is used for video ingestion, processing, hosting, and playback in video testimonial workflows. Place of subprocessing: United States.

PostHog

PostHog is used for product analytics in the Famewall application experience. Place of subprocessing: United States based.

Amplitude

Amplitude is used for product and growth analytics across Famewall workflows. Place of subprocessing: United States.

Crisp

Crisp is used for customer support chat and support message handling on the product and marketing site. Place of subprocessing: European Union, including the Netherlands and Germany.

Common questions

Do you support GDPR requests?

Yes. For access, correction, export, or deletion requests, email contact@famewall.io. Our Privacy Policy describes these rights in more detail.

Do you have a DPA or public subprocessor list?

This page includes a public subprocessor overview based on the current Famewall codebase and website tooling.

Need a security answer for procurement?

If a customer needs a questionnaire response, privacy clarification, or confirmation about a specific workflow, email contact@famewall.io and include the exact request.