DebutDeploy / security
Deploy an app
Home Pricing Compare providers Platform pages Migrate FAQ Status Compare my bill Deploy an app
Trust

Security you can deploy on.

Every app runs isolated on enterprise-grade European infrastructure, secrets are encrypted, and our upstream infrastructure credentials never reach your browser. Here's how we keep the platform safe.

Isolated workloads

Every application and database runs in its own fully isolated container with clean resource boundaries — your workloads stay genuinely separate.

Encrypted in transit

All traffic is served over HTTPS with automatically-issued TLS certificates via Traefik. No plaintext endpoints.

Secrets stay secret

Environment secrets are encrypted at rest, and our upstream infrastructure credentials live only on our server — never in the browser or your repo.

EU data residency

Compute and storage run in enterprise-grade data centres in Germany and Finland, inside the EU.

Scoped access & tokens

Sign in with GitHub or Google. Programmatic API tokens are scoped (read-only or full) and revocable, with per-resource ownership checks.

Least-privilege deploys

Repository access uses a single read-only deploy key; we request only the GitHub scopes needed to build and deploy.

Responsible disclosure. Found a vulnerability? Email security@debutdepoly.com with details and steps to reproduce. Please don't access other customers' data or degrade the service while testing. [Add formal disclosure terms / any certifications — SOC 2, ISO 27001 — only once actually held.]