Trust

Trust & compliance

What we run, who processes data, how long we keep it, and how to report a vulnerability. Written to be checked, not to be taken on faith.

Live status

These checks run in your browser, now, against our public health endpoints. They are a point-in-time read, not a 24/7 monitor with incident history.

  • Sign in and identityAccounts, SSO, and API-key authentication.Checking...
  • Files, sync, and sharingMetadata, locks, uploads, and share links.Checking...

“No response” can mean the service is unreachable from your network (VPN, proxy, ad-blocker) rather than an outage. If something looks wrong, tell us and we’ll confirm from inside.

Subprocessors

These are the providers that process data for the hosted service. Self-hosted and bring-your-own-storage deployments move most of this onto infrastructure you control.

ProviderPurposeData
CloudflareHosting for the hub, identity service, dashboard, and this site; default block storage; CDN and network security; optional Turnstile bot detection on forms; video-preview rendering.File blocks (encrypted for private projects on paid plans; plaintext for Free and public projects and for direct git-LFS uploads), metadata, and request and website traffic.
StripePayments, subscriptions, and invoicing.Billing contact and payment data. Card details never reach our servers.
PostmarkTransactional email (invites, notifications, alerts).Email address and the notification content (event metadata, never file contents).
n0 (iroh relay network)NAT traversal and peer discovery when two machines can’t connect directly.Connection metadata. Relayed traffic stays encrypted between peers.
Google AnalyticsVisitor analytics on the public marketing and docs pages only.Page-view data (URL, referrer, approximate location). No file content; not loaded on public project pages, the dashboard, or the desktop client.
Google FontsWeb fonts for this site.Font requests, which carry the page URL as referrer.
GitHubDistribution of the git-LFS agent and release artifacts.Download metadata only.
Customer-configured providersAn organization’s own identity provider, object storage, or webhook endpoints, only when it enables them.Whatever the configuration sends, under your terms.

We update this list when providers change. For a signed data processing agreement (DPA) or advance-notice terms, contact us.

Where your data lives

Paid plans can pin an organization’s metadata and block storage to an infrastructure-enforced EU or US region at signup, at no extra cost, chosen once and permanent. Free organizations use shared storage and are not eligible. Region selection covers the project data and metadata the service identifies as resident; account, billing, support, and security records are processed in the United States. Read the full detail in the Privacy Policy and Deployment Topologies.

Retention and deletion

  • Files. Deleting moves an entry to trash; restore is available until the retention window passes. “Delete Forever” and “Empty Trash” remove content ahead of the sweep, and project and org deletion are owner-triggered and audited.
  • Version history. Kept per the organization’s retention settings, so rollback works for as long as the plan promises.
  • After deletion. Copies can remain briefly in processing queues, caches, replicas, and security logs before being overwritten or de-identified. Billing, legal, acceptance, audit, and support records are kept longer where law or dispute resolution requires it.

The operative wording is in the Privacy Policy, section 7.

Compliance posture

We don’t claim certifications we don’t have. SOC 2 Type I is on the roadmap and not yet started; Type II follows. We are not FedRAMP-authorized. Today we complete security questionnaires, share our architecture, and map controls directly with your security team, pre-sales included on every plan. The Security page lists what is enforced, what is a deliberate boundary, and what is planned.

Reporting a vulnerability

Use the contact form and put “Security vulnerability” in your message. Please don’t include credentials, personal data, or working exploit details in that first message; we will arrange a secure channel for follow-up.

  • Scope. Our production services and desktop clients. Third-party providers (for example Cloudflare or Stripe) have their own programs.
  • Our commitment. We aim to acknowledge reports within two business days and to keep you updated until resolution. We don’t run a paid bounty program.
  • Good-faith research. We won’t pursue action against research that stays in scope, avoids privacy violations and data destruction, and doesn’t disrupt the service. Tell us before publishing, and we’ll credit you if you’d like.

A machine-readable copy of this policy is at /.well-known/security.txt.

Need the paperwork?

We answer security questionnaires, sign DPAs, and walk through the architecture with your team.