You upload the most sensitive artifact you produce: a production binary. For most teams that is a bigger perceived risk than a store rejection, so security is a product requirement here, not a policy afterthought. This page says plainly what we do, and what we do not yet do.
Infrastructure
- Everything runs on EU infrastructure with EU vendors; the single exception is payments through Stripe.
- Every customer's data is strictly isolated from every other customer's.
- Production and test environments are fully separated; test environments never contain customer builds.
- Strict firewall rules and private networking between internal services.
Encryption
- All traffic is encrypted in transit with TLS.
- All stored data, findings and backups are encrypted at rest.
- Credentials are hashed with a modern algorithm, never stored in plain text.
Your build
Your uploaded binary is processed in an isolated scan environment and destroyed the moment the scan finishes. We keep the findings and their evidence for your retention window, never the binary itself. We never ask for source code, signing keys or repository access. The full lifecycle is on the EU-first data handling page.
Access
- Internal access to customer data is limited to the few people who need it, on a least-privilege basis.
- Every internal access is logged.
- Nobody at AppCompliance browses customer findings out of curiosity; access happens for support you asked for, or for incident response.
Continuity and incidents
- Encrypted backups with tested recovery procedures.
- A documented incident response procedure; affected customers are informed without undue delay, in plain language, with what happened and what we did.
- Maintenance and incidents are announced on the status page.
Responsible disclosure
Found a vulnerability in AppCompliance? Please report it to security@appcompliance.io and give us a reasonable window to fix it before publishing. We read every report, we respond quickly, and we credit researchers who want to be credited. We do not run a paid bounty program yet, and we say so rather than imply one.
What we do not claim
We do not yet hold SOC 2 or ISO 27001 certification, and we will not display badges we have not earned. What we offer instead: this documentation, honest answers to your security questionnaire, and a data processing agreement before you upload anything. Ask via security@appcompliance.io and expect a reply within one business day.