Trust & Status
Last updated: Jul 3, 2026
Service status — private beta
Live component health is on the status page (refreshed from GET /api/status). Uptime monitors should use GET /api/health — it returns ok, degraded, or down without marketing claims.
- No measured 30-day SLO baseline — required before paid GA marketing.
- Synthetic probes:
bun script/synthetic-health-probe.ts(operator-run). - SOC 2 Type II: not certified.
Subprocessors
When you use the hosted console, personal data may be processed by the following categories of subprocessors. Self-hosted deployments control their own infrastructure stack. Enterprise buyers: see the draft Data Processing Agreement (counsel review pending).
| Subprocessor | Purpose | Region |
|---|---|---|
| Forgejo (nforge.dev) | Source hosting, CI, container registry | Operator-selected |
| Stripe | Payment processing (when billing enabled) | US / EU |
| OAuth sign-in | Global | |
| GitHub | OAuth sign-in and git integrations | Global |
| AWS / cloud SMTP | Transactional email (when configured) | Operator-selected |
Data handling
GDPR portable export: GET /api/account?export=1 (sync) or POST /api/account?action=schedule-export (async stub). Account erasure: DELETE /api/account with confirmation body. See Privacy Policy — counsel review for GA is pending.
Enterprise SSO
OIDC and SAML login are available for verified email domains with active connections. Sign-in starts at /sso/login?domain=, which routes to the appropriate flow; SAML is SP-initiated only (an AuthnRequest via HTTP-Redirect, bound to the browser that started it), so a login started from an identity provider's app dashboard is refused.