Trust center
Company security
How the company protects its own systems, code and the little customer data it holds.
Some commitments on this page are being put in place before the first paid release. Each item's status is marked.
The company holds no customer firewall data. It does hold source code, signing pipelines, and customer account and billing records. These policies cover them; summaries are below and full policies will be in the security pack.
| Policy | Summary |
|---|---|
| Access control | Least privilege; access reviewed quarterly |
| Authentication | Multi-factor authentication on every company account, including source control, email and payments |
| Devices | Full-disk encryption, automatic updates and screen lock on every company device |
| Source code | Private repository with a protected main branch; every change by pull request with automated checks |
| Release signing | Release images signed keyless from CI; no signing key is kept on a personal device |
| Incident response | Documented process; customers notified of incidents that affect them without undue delay |
| Vendor management | Vendors limited to the subprocessors list and reviewed yearly |
| Backup | Source and business records backed up off-site |
Last updated 2026-10-04.