How we handle account and service security
Current practices, service boundaries, and the best way to reach us with a security question or report.
HTTPS and sign-in
Customer-facing sites use HTTPS with managed TLS certificates. Account sign-in uses a one-time link.
Keep your application secrets, source repositories, and external service credentials secure.
Restore support
Recovery is support-assisted for eligible hosting products. Tell us what happened, and we will confirm the available recovery path.
Bring-your-own databases and external services remain under the recovery policies of the provider you chose.
Passwordless accounts
We don't store passwords for customer accounts. Sign-in uses a one-time link sent to your email.
There is no password to create or reset.
Access boundaries
Access to production systems is restricted to authorized support and platform operations.
App Hosting is intentionally narrow: keep your own database, API, CMS, or backend credentials in the systems you choose.
Regional placement
New App Hosting projects can be placed in US East, US West, or EU. Choose the placement that fits your users and requirements.
The Privacy Notice and Data Processing Addendum explain the data-handling terms that apply to the service.
Incident response
If we confirm a security incident affecting customer data, we investigate and notify affected customers.
Public service incidents are reflected on the status page when appropriate.
Data deletion
After cancellation, production data is normally retained for up to 30 days to support export or restoration, then removed from production systems subject to legal-retention needs.
Backup copies age out on their applicable retention schedule.
Data Processing Agreement
The current Data Processing Addendum is available online.
Contact us before you buy if you have a specific requirement.
Service providers
We rely on service providers for:
Payment processing for billing and payments.
Host Little account and notification email delivery.
Application and site compute infrastructure.
DNS and TLS infrastructure.
Security scope
The status page shows the public endpoint checks we run. It does not measure every customer workload or promise a service level. For formal audit or compliance requirements, email [email protected] and we'll confirm the right support path before you buy.