CellDelta Request access
Security & Trust

Security & Trust

Last updated: 23 June 2026

01Security model

CellGuard is an independent, deterministic validator for spreadsheet edits to financial models. It sits between an AI assistant and your model and returns a block / flag / pass verdict on a tamper-evident audit record. Its security properties follow directly from what it is, and from what it deliberately is not:

Because no model runs inside verification, much of the data-exposure surface that AI tools carry is simply not present.

02Data protection

We apply technical and organisational measures appropriate to the risk. The measures below are present in the service as deployed:

Single-tenant per deployment. Each deployment runs as a single tenant and uses one shared approval credential. Sessions are isolated from one another by an unguessable random session_id, not by per-user identity. We do not present this as a multi-tenant access-control boundary: organisations that need strict per-tenant isolation should use a dedicated deployment or self-host.

03Data handling & retention

What we process, and what we keep

Audit retention. On the managed service the hash-chained audit log is durably retained in an append-only store for 24 months (configurable), then automatically purged. Entries hold an ops_digest and metadata only — never cell values. Self-hosted deployments set their own retention and control the storage.

Retention summary

We minimise by default: digests rather than values, and no analytics, advertising or tracking cookies. See our Privacy Policy for the full data-protection detail.

04Hosting & sub-processors

The managed service and the celldelta.ai website run on a small, fixed set of vendors, under data-processing terms. The principal sub-processors are:

Principal sub-processors (managed service)
Sub-processor Purpose Location Transfer safeguard
Railway Corporation Cloud hosting, compute and ephemeral storage for the managed service and MCP server. United States EU‑US Data Privacy Framework (certified) and/or EU Standard Contractual Clauses.
Cloudflare, Inc. CDN, edge and DNS proxy (processes visitor IP for delivery, security and rate-limiting). United States EU Standard Contractual Clauses, and the EU‑US Data Privacy Framework where the recipient is certified.
Brevo (Sendinblue) Transactional email / SMTP relay for the access-request notification and account email. European Union Processed in the EU; for any US leg, Sendinblue Inc. is covered by the EU‑US Data Privacy Framework and SCCs.

The EU‑US Data Privacy Framework remains valid: the EU General Court upheld it on 3 September 2025 in Latombe (T‑553/23); a CJEU appeal is pending.

The full list, including our source-code host and business mailbox provider, with purposes and transfer safeguards, is on our Sub-processors page. Self-hosted deployments use no sub-processors for customer content. No AI or model-hosting provider acts as our sub-processor, because verification runs no model.

05Data residency

The managed service is currently hosted in the United States (Railway), with Cloudflare at the edge. Submitting the website access form, or using the managed service, therefore involves a transfer outside the European Economic Area, made under the safeguards described above (DPF certification and/or SCCs).

We do not offer EU data residency as a default on the managed service today. EU-region and on-premises deployment are available for self-hosted and enterprise customers: in a self-hosted deployment your workbooks, edits, verdicts and audit records stay within your own perimeter and never reach us. If EU or in-region residency is a requirement, contact us about a self-hosted or enterprise deployment.

06Governance & compliance posture

CellDelta is operated by an EU-established controller (Krzysztof Dalewski, sole proprietor trading as CellDelta, Warsaw, Poland). Our posture:

What we do not claim. CellDelta is not SOC 2 audited and not ISO/IEC 27001 certified. We will say so plainly until and unless that changes. Where the product cannot yet do something, such as default EU data residency, we scope it to self-hosted or enterprise rather than imply it is generally available.

07Responsible disclosure

We welcome reports from security researchers and treat good-faith disclosure as a contribution, not a threat. This policy is aligned with ISO/IEC 29147 (vulnerability disclosure) and ISO/IEC 30111 (vulnerability handling). Alignment is not certification.

Scope

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised, we will not pursue or support legal action against you for it, and we will work with you to understand and resolve the issue. Good faith means: you stay within the scope above; you avoid privacy violations, data destruction, and any degradation of the service; and you give us a reasonable opportunity to remediate before disclosing publicly.

How to report

Email [email protected] with enough detail to reproduce the issue (affected URL or endpoint, steps, and impact). Please do not include customer workbook content or other personal data in your report; a redacted proof of concept is sufficient. We run no paid bug-bounty program.

Acknowledgement target. We aim to acknowledge a valid report within 5 business days, keep you updated as we triage and remediate, and credit you on request once the issue is resolved.

Out of scope

A machine-readable contact is published at /.well-known/security.txt (RFC 9116).

08Contact

Security reports: [email protected]. Everything else, including a DPA or a copy of a transfer safeguard: [email protected].

Krzysztof Dalewski (CellDelta)
ul. Capri 4/18, 02‑762 Warsaw, Poland
NIP 5214160761 · REGON 544460460
[email protected]

You can also contact the Polish supervisory authority — Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00‑193 Warsaw, uodo.gov.pl.