Security & privacy
Your client deck stays private — not searchable on Google.
The quick, free ways to publish a page were never built for confidential client work — most put your page on the public web, where Google can index it by default. Pagelive is built the other way around: link-gated, optionally password-gated, and kept out of search. So a proposal, deck, or dashboard goes only to the people you send it to.
noindex by defaultisolated content planePBKDF2 passwordsno AI trainingno data sellingCloudflare SOC 2 Type II infrastructure
Noindex by default
It won’t show up on Google
Every page ships with a robots meta tag and an X-Robots-Tag: noindex, nofollow response header — the two signals search engines use to decide whether to list and follow a URL. Both say no by default, so your client deck stays out of search results. You can opt a page into indexing only if you explicitly choose to.
Illustrative demonstration of default behaviour. No real customer data.
Isolated content plane
Your pages are walled off from your account
Published pages serve from a separate content plane — pagelive.site (and your own custom domain with Founding) — that’s isolated from the control plane where your dashboard, login, and billing live. A served page can’t reach your account data. If a page were ever compromised, the blast radius stops at that page.
- • Dashboard
- • Auth & accounts
- • Billing
- • Your published pages
- • Custom domains (Founding)
- • noindex · edge-gated
Password protection
Lock a page — with a password even we can’t read
Any page can be password-protected. The password is PBKDF2-hashed — never stored in plaintext, and not visible to us. The gate is enforced at the edge with signed cookies, so only people who have both the link and the password can open the page. Lose the password? You reset it; we can’t recover the original because we never had it.
Hashed, not stored
PBKDF2-hashed at rest — never plaintext, never visible to us.
Edge-gated
The check runs at the edge before any content is served.
Signed cookies
A verified visitor gets a signed cookie — no shared secret leaks to the page.
What we never do
No training on your content · no selling your data
We never use your content — or anything inside your pages — to train AI or ML models, ours or anyone else’s. Your work is yours.
We never sell your data, and we never sell or rent the email addresses of the people you share pages with. Read the privacy policy →
Infrastructure
On Cloudflare’s SOC 2 Type II–audited infrastructure
Pagelive runs entirely on Cloudflare — Workers, D1, and R2 — which operates on SOC 2 Type II–audited infrastructure. That means DDoS protection, TLS everywhere with automatic per-domain certificates, and your data on a hardened, globally distributed network.
For the security lead reviewing this
Do you train AI on what we upload? +
No. We never use your content — or anything in your pages — to train AI or ML models, our own or anyone else’s. It’s in our terms.
Where is content hosted, and how secure is it? +
Entirely on Cloudflare — Workers, R2, and D1 — which operates on SOC 2 Type II–audited infrastructure, in an EU data region. Your pages serve from an isolated content plane that’s walled off from the dashboard, auth, and billing.
Will this show up on Google, or can it be scraped? +
No — pages are noindex by default. We send a robots meta tag plus an X-Robots-Tag: noindex, nofollow header that tells search engines not to list or follow it. You can opt a page into indexing only if you explicitly choose to.
Who can access a page, and how are passwords handled? +
Access is by link, with an optional password. Passwords are PBKDF2-hashed — never stored in plaintext, and we can’t see them. The gate is enforced at the edge with signed cookies, so only people with the link (and the password, if set) can open the page.
Do you sell our data or our recipients’ emails? +
No. We never sell your data, and we never sell or rent your recipients’ email addresses. See our privacy policy for the full picture.
Do we lose interactivity, like with a PDF? +
No. Pagelive serves your live HTML page — animations, responsive layout, and interactive elements all keep working. Nothing is flattened into a static image.
The questions a CTO actually asks before a confidential document goes out — answered plainly.
Compliance & data location
EU data region, GDPR-minded, with a clear takedown path
Your data is processed in an EU data region. Analytics are privacy-first — viewer IPs are salted-hashed, never stored raw, with coarse country only. If a page ever needs to come down, abuse and takedown requests have a clear path and we can disable a page from the edge with one flip.
Send your next deck on a link that can’t leak.
Noindex by default, isolated content plane, optional password. Free to start.