Appstrate
[Security]

Security posture, in detail.

How we build, host, and operate Appstrate. Honestly stated. Audit-ready.

[01 · Compliance roadmap]

Where we are today

We don't claim certifications we don't have. Current status:

GDPR
Compliant
SOC 2 Type II
In progress — Q3 2026
ISO 27001
Planned — 2026
HIPAA
BAA available on Enterprise
PCI-DSS
Not applicable (no card data)

[02 · Technical controls]

How we secure the platform

Sandboxed execution

Every run in an isolated Docker container. No host access.

Credential isolation

Sidecar proxy pattern. Agents never see secrets.

AES-GCM at rest

32-byte key. Rotation supported. Envelope encryption on Enterprise.

TLS 1.3 in transit

HSTS preloaded. Modern ciphers only.

RBAC throughout

78 typed permissions. Every route gated.

SSRF hardening

Outbound URLs validated. No metadata leaks.

Rate limiting

Redis-backed. Per user, per IP, per route.

Audit logs

Every privileged action logged. Exportable on Enterprise.


[03 · Sub-processors]

Who touches your data

Full list, updated monthly. Changes announced 30 days in advance.

VendorPurposeRegion
CloudflareCDN + edge hostingGlobal / EU-only option
AWSStorage (S3)EU-west-3 (Paris)
StripeBillingIreland (EU)
ResendTransactional emailEU
SentryError monitoringEU

[04 · Portability & exit strategy]

You can leave. With everything.

Data, agents, and configuration are all exportable via the API — applications, end-users, credentials (encrypted), and run history. Agents are packaged per the open AFPS spec, so they run on any compliant host. The platform itself is Apache 2.0 — no opaque dependency, no source-available trickery. If we disappear, your agents keep running.


[05 · Responsible disclosure]

Found a vulnerability?

Email [email protected]. GPG key available at /security/gpg.txt.

  • · Ack within 2 business days
  • · Remediation timeline within 10 business days
  • · Public credit on Security page (opt-in)
  • · No legal action against good-faith researchers

Request the full security package.

SOC 2 progress report, penetration test summary, SBOM, DPA — all under NDA.