Every app runs isolated on enterprise-grade European infrastructure, secrets are encrypted, and our upstream infrastructure credentials never reach your browser. Here's how we keep the platform safe.
Every application and database runs in its own fully isolated container with clean resource boundaries — your workloads stay genuinely separate.
All traffic is served over HTTPS with automatically-issued TLS certificates via Traefik. No plaintext endpoints.
Environment secrets are encrypted at rest, and our upstream infrastructure credentials live only on our server — never in the browser or your repo.
Compute and storage run in enterprise-grade data centres in Germany and Finland, inside the EU.
Sign in with GitHub or Google. Programmatic API tokens are scoped (read-only or full) and revocable, with per-resource ownership checks.
Repository access uses a single read-only deploy key; we request only the GitHub scopes needed to build and deploy.
[Add formal disclosure terms / any certifications — SOC 2, ISO 27001 — only once actually held.]