Security Statement contents
Who We Are
Cited.ie is an AI search visibility service for specialist local and service businesses, launching first with Irish law firms. The website https://cited.ie is operated by Gift Phiri and Igor Fossa Silva trading under the registered business name Cited (Business Name Registration No. 785706), 271 Harolds Cross Road, Dublin, D6W CX39, Ireland. Contact: info@cited.ie.
Security Approach
Cited.ie takes a practical, risk-aware approach to website and enquiry security. Our approach is based on collecting only the information needed for an enquiry or service request; avoiding confidential legal matter details through public forms; using secure hosting and database providers; handling form submissions server-side; restricting access to enquiry data; protecting forms against spam and misuse; using secure connections; keeping sensitive keys and credentials out of public website code; and reviewing controls as the business develops.
No website or online service can guarantee absolute security, but Cited.ie aims to use reasonable technical and organisational measures appropriate to the current stage of the business.
Hosting and Infrastructure
Cited.ie currently uses Vercel for website hosting and deployment. Vercel provides hosting and deployment infrastructure for modern web applications. Cited.ie is responsible for configuring and operating its own website securely, including the website code, forms, integrations, content, access controls and connected services.
Database and Enquiry Storage
Cited.ie uses Supabase to store enquiry and lead data submitted through website forms. The database is configured so that lead and enquiry tables are not publicly readable; Row Level Security is enabled; access is limited to authorised Cited.ie administrators; service keys are used server-side only; private keys are not exposed in browser code; the database is used only for appropriate enquiry and business records; and retention and deletion review dates are stored with enquiry records.
Server-Side Form Handling
Cited.ie forms submit through a secure server-side route. The browser does not write directly to private database tables. The form flow validates required fields and consent, checks anti-spam controls, sanitises input, writes approved submissions to the database, and returns a clear success or error message to the user. This approach reduces the risk of exposing database credentials or allowing uncontrolled browser-side database writes.
Form Protection
Cited.ie uses several form-protection measures:
- Required-field validation — reduces incomplete submissions
- Email and URL validation — improves data quality and avoids malformed inputs
- Consent validation — confirms the user understands the stated processing purpose
- Honeypot field — helps detect simple automated spam
- Rate limiting — reduces excessive submissions and abuse
- Cross-origin request checks — rejects form posts from other websites
- Server-side validation — ensures checks happen before storage, not only in the browser
These controls help protect the website against spam, automated submissions, malformed input and misuse. They do not guarantee that all spam or abuse will be blocked.
Information We Ask Users Not to Submit
Cited.ie public forms are intended for business enquiries only. Please do not submit confidential legal matter details, solicitor client case information, privileged information, special category data, sensitive personal data, medical information, financial account details, client documents, passwords, authentication codes or payment card details.
Access Controls
Access to Cited.ie website systems, hosting, domain, code and enquiry data is limited to authorised users only — at launch, the founders and any approved technical support required to operate the website. Cited.ie uses strong passwords, multi-factor authentication where available, limited admin access, private repositories, environment variables for secrets, and regular review of who has access. Access is removed when it is no longer needed.
Credentials and Secrets
Cited.ie does not expose private credentials in public website code. This includes database service keys, database credentials, email provider API keys, hosting secrets, private tokens, deployment secrets and admin passwords. Secrets are stored in secure environment variable settings provided by the hosting platform and are not committed to code repositories.
Email Notifications
Cited.ie may use email notifications to alert authorised users when a new enquiry is submitted. Where email notifications are used, personal data in the email body is minimised: a notification states that a new enquiry has been received and its type, while full details remain inside the secure database.
Local Storage and Cookie Preferences
Cited.ie uses local storage to remember functional preferences such as light or dark mode and cookie preference choice. These settings are stored in the user's browser and are not used to store confidential legal matter details, form messages, solicitor client information or sensitive personal data. Further information is available in the Cookie / Local Storage Policy.
Security Headers and Transport Security
Cited.ie uses HTTPS and appropriate security headers, including HTTP-to-HTTPS redirects, HSTS, Content Security Policy, frame protection, X-Content-Type-Options, Referrer Policy and Permissions Policy. These controls help reduce common browser and web security risks.
Rate Limiting and Abuse Protection
Cited.ie uses rate limiting and equivalent controls to reduce excessive form submissions, spam and automated abuse. If spam or abuse increases, Cited.ie may strengthen these protections with provider-level firewall rules, IP-based rate limiting, more advanced bot protection, or additional server-side checks — balancing abuse protection with accessibility and usability.
Third-Party Providers
Cited.ie uses third-party service providers to operate the website and related systems: hosting and deployment (Vercel), database (Supabase), and domain/DNS providers. Email, notification, analytics or support tools may be added in the future. Cited.ie reviews third-party providers before use and documents them in the Privacy Notice or internal processor records where appropriate.
Future Support or Chat Tools
Before any support or chat tool is added, Cited.ie will review whether the tool collects personal data, sets cookies or uses local storage, transfers data outside Ireland or the EEA, loads third-party scripts, requires consent before loading, requires a data processing agreement, and fits the website's privacy and security standards.
Backups and Data Recovery
Cited.ie maintains a practical backup and recovery approach appropriate to the stage of the business. This may include database exports, provider-level backups where available, secure storage of important business records, access to deployment history, version-controlled code and recovery steps for website errors or failed deployments.
Data Retention and Deletion
Cited.ie does not keep enquiry data indefinitely. Lead and enquiry data includes review and deletion dates. Unconverted enquiries are reviewed after 12 months of inactivity; spam or test submissions are deleted as soon as practical; active client records are kept while the service relationship is active; completed service records are retained only for a limited service-history period unless a longer lawful reason applies; accounting records are retained for the period required by applicable business and tax obligations. More detail is provided in the Privacy Notice.
Incident Handling
If Cited.ie becomes aware of a security issue affecting website systems or personal data, Cited.ie will assess the issue and take appropriate action. This may include investigating and containing the issue, securing affected systems, reviewing what data may be affected, contacting relevant providers, notifying affected individuals where required, notifying the Data Protection Commission where legally required, and improving controls to reduce future risk.
User Responsibilities
Users should submit only appropriate business enquiry information, avoid sending confidential legal matter details or sensitive personal data, use accurate contact details, avoid submitting spam or malicious content, avoid attempting unauthorised access, avoid interfering with the website or forms, and use secure devices and browsers where possible. Cited.ie is not responsible for information that users choose to submit in breach of form warnings or website terms.
No Absolute Security Guarantee
Cited.ie takes reasonable steps to protect website systems and submitted information. However, no website, hosting provider, database provider, email system or internet transmission can be guaranteed to be completely secure. Users should consider the sensitivity of information before submitting it through any website form.
Changes to This Security Statement
Cited.ie may update this Security Statement as the website, infrastructure, providers or security controls change. The latest version will be published on this page with an updated "Last updated" date.

