Trust Center

Security & Trust at DeployMeter

Your engineering data is sensitive. Here is exactly how we protect it — what is encrypted, who can see what, where data lives, and what we are honest about not having yet.

Last updated: 2026-07-04

Data protection

Encryption and isolation are built into the platform, not bolted on.

Encryption at rest

Integration tokens and other credentials are encrypted with AES-256-GCM before they ever reach the database. Encryption keys live only in the production environment.

Encryption in transit

All traffic between your browser, our APIs and our integrations is encrypted with TLS. Inbound webhooks are signature-verified.

Multi-tenant isolation

Every single query is scoped to your organization. There is no code path that can read another customer's data.

Access control

Deny by default, at every layer — roles, scopes and per-category visibility.

Role-based access

Three roles — Owner, Lead, Member — with deny-by-default permissions. Leads only see the part of the organization they are anchored to, enforced server-side.

Multi-level visibility

A dedicated visibility layer controls whether data is exposed per individual, as aggregates, or not at all — and sub-teams can only restrict it further, never widen it.

Immutable audit log

Policy changes, permission grants and access to sensitive data are recorded in an append-only audit log, exportable as CSV.

GDPR & data privacy

EU-hosted, with self-service data rights — not a support-ticket queue.

EU data residency

All production data is hosted in Germany (Hetzner, EU). No customer data is replicated outside the EU.

Self-service data rights

Full organization export, developer anonymization or deletion, and organization offboarding with a 30-day grace period — all self-service, all recorded in the audit log.

Configurable retention

Retention for raw data such as analyzed diffs and webhook payloads is configurable per organization.

Data Processing Agreement

Our standard DPA under Art. 28 GDPR — including the subprocessor list, technical measures and Standard Contractual Clauses by reference — is available for download.

Download DPA template

Compliance roadmap

SOC 2 Type I — audit-ready

We do not hold a SOC 2 certification yet, and we won't claim otherwise. Our security policies are written and published, and the practices they describe are in place today. The formal Type I audit starts with our first enterprise customer that requires it — with policies and evidence ready, the path to the report is short.

Published policies

  • Information Security Policy
  • Access Control Policy
  • Incident Response Policy
  • Vendor Management Policy

Current versions are available on request via security@deploymeter.com.

Subprocessors

We run DeployMeter on a deliberately small set of vendors. Each one is bound by a data processing agreement.

ProviderPurposeLocation
HetznerCloud hosting — all production dataGermany (EU)
ClerkAuthentication and organization managementUnited States
StripeBilling and paymentsUnited States
AnthropicAI analysis of pull request diffs — diffs only, never credentials or secretsUnited States
SlackNotifications (opt-in)United States
GitHub / GitLabSource data: pull requests, commits, pipelinesUnited States

Transfers outside the EU are covered by Standard Contractual Clauses (EU 2021/914).

Responsible disclosure

Found a vulnerability? We want to hear about it. Email us and we will respond within two business days. Good-faith research is welcome.

security@deploymeter.com

Under Construction

Enter access code to continue