Report any vulnerability via the security inbox below. We acknowledge within one business day, ship a fix or mitigation as fast as the issue warrants, and publish a writeup with credit (opt-out available) once any affected customer has had time to update. We follow a 90-day disclosure window unless the issue is actively exploited.
Send reports to [email protected] . PGP key fingerprint and full public key are published at /.well-known/security.txt. Include reproduction steps, affected component, and any proof-of-concept you ran. We'll mirror our own report format back to you when we triage.
Customer data is hosted in the EU: the platform runs in Helsinki, Finland (Hetzner) and scan artifacts are stored in Stockholm, Sweden (AWS eu-north-1). EU residency is the default on every plan, including Free. Other regions are available by contract where supported. We do not sell customer data, do not share it with third parties beyond named subprocessors (Paddle for billing, Resend for transactional email, DeepSeek and Anthropic for AI runs you trigger), and do not train models on it. A signed DPA is available on request to [email protected] .
The features below are what your SOC 2 / ISO 27001 / NIS2 / GDPR Art. 32 auditor actually reads, not promises, not roadmap items. Click any link for the docs.