Trust
What we do — and what we do not claim.
EU hosting & isolation
Cloud instances run in EU data centers. Each customer gets a dedicated instance — not a row in a shared table. Your data never shares a database with another customer's data.
Secrets never live in documents
Credentials are referenced as cred:// pointers — never stored inside label definitions, flow configurations, logs or test data. The secret store is separate from the document store by architecture, not by policy.
Outbound-only runners
Runners initiate all connections. No inbound firewall rule is needed on your network. This is an architectural property, not a configuration option.
Signed binaries
Every release is signed. Checksums are published alongside the binaries. Verify before you run.
Certificate rotation
Runner certificates are automatically rotated at two-thirds of their validity window. The rotation window is computed from the actual certificate lifetime — never from a hardcoded 90-day constant. Failed rotations trigger an alert.
Quality verification
Every label renderer change is verified against golden-file pixel diffs at 203, 300 and 600 dpi. A single changed pixel requires a documented, reviewed justification. This is not a test suite — it’s a quality gate that prevents silent visual regressions.
DPA (AVV)
A Data Processing Agreement is available for download: /legal/dpa/
Responsible disclosure
Found a security issue? Contact us at /security/. We take reports seriously and respond promptly.