TRUST · SECURITY

Security, built in by default.

How we protect your code — from the moment you press enter to the moment it’s discarded.

security-overview.md

read-only

soc 2

Type II · audited yearly

encryption

AES-256 · TLS 1.3

code retention

0 s by default

pen testing

Quarterly, third party

bug bounty

Up to $10,000

TL;DR

Security at a glance

SOC 2 Type II

Independently audited every year. Report available under NDA.

SOC 2 Type II

Independently audited every year. Report available under NDA.

SOC 2 Type II

Independently audited every year. Report available under NDA.

Encrypted everywhere

AES-256 at rest and TLS 1.3 in transit, with managed keys.

Encrypted everywhere

AES-256 at rest and TLS 1.3 in transit, with managed keys.

Encrypted everywhere

AES-256 at rest and TLS 1.3 in transit, with managed keys.

Zero code retention

Prompts and code are processed in memory and discarded.

Zero code retention

Prompts and code are processed in memory and discarded.

Zero code retention

Prompts and code are processed in memory and discarded.

Open bug bounty

Rewards of up to $10,000 for valid security reports.

Open bug bounty

Rewards of up to $10,000 for valid security reports.

Open bug bounty

Rewards of up to $10,000 for valid security reports.

§01

How your code flows

Every request follows the same short path. Nothing about your code is written to disk, logged or reused once your response is returned.

01

Your editor

CLI · IDE · API

02

In transit

TLS 1.3 · HSTS

03

Isolated worker

In-memory only

04

Diff returned

Signed · streamed

05

Discarded

0 s retention

// Enterprise workspaces can pin workers to the EU or run them inside their own VPC.

§02

Security controls

Security is part of how we build, not a layer on top. These controls apply to every plan.

Encryption

AES-256 encryption at rest

TLS 1.3 for all traffic

Keys managed in a cloud HSM

Encryption

AES-256 encryption at rest

TLS 1.3 for all traffic

Keys managed in a cloud HSM

Access control

SSO and hardware keys for all staff

Least-privilege, time-boxed access

Quarterly access reviews

Access control

SSO and hardware keys for all staff

Least-privilege, time-boxed access

Quarterly access reviews

Isolation

Per-request, single-tenant workers

No shared state between customers

Restricted network egress

Isolation

Per-request, single-tenant workers

No shared state between customers

Restricted network egress

Monitoring

24/7 alerting and on-call

Tamper-evident audit logs

Automated anomaly detection

Monitoring

24/7 alerting and on-call

Tamper-evident audit logs

Automated anomaly detection

Secure development

Review required on every change

Dependency and secret scanning

Signed, reproducible releases

Secure development

Review required on every change

Dependency and secret scanning

Signed, reproducible releases

Resilience

Multi-zone infrastructure

Encrypted daily backups

Recovery tested every quarter

Resilience

Multi-zone infrastructure

Encrypted daily backups

Recovery tested every quarter

§03

Compliance

We maintain independent attestations and contractual commitments so your security and procurement reviews move quickly.

SOC 2 Type II

AUDITED

Annual audit of security, availability and confidentiality controls.

SOC 2 Type II

AUDITED

Annual audit of security, availability and confidentiality controls.

GDPR

COMPLIANT

EU data residency and a Data Processing Agreement for every customer.

GDPR

COMPLIANT

EU data residency and a Data Processing Agreement for every customer.

CCPA

COMPLIANT

We act as a service provider and never sell personal information.

CCPA

COMPLIANT

We act as a service provider and never sell personal information.

§04

Sub-processors

These third parties process customer data on our behalf under written agreements. We give customers 30 days’ notice before adding a new sub-processor.

vendor

purpose

location

Amazon Web Services

Amazon Web Services

Cloud hosting and storage

US · EU

Cloudflare

Cloudflare

Network security and CDN

Global

Datadog

Datadog

Infrastructure monitoring

US · EU

Stripe

Stripe

Payment processing

US

Postmark

Postmark

Transactional email

US

Zendesk

Zendesk

Customer support

US

§05

Responsible disclosure

If you believe you’ve found a vulnerability, email security@codecraft.dev with the details. We acknowledge reports within 24 hours, keep you updated as we fix the issue and credit researchers who want recognition.

Please don’t access other customers’ data, run denial-of-service tests or use social engineering. Good-faith research that follows these rules is welcome and won’t lead to legal action.

/.well-known/security.txt

Contact: mailto:security@codecraft.dev

Encryption: codecraft.dev/pgp-key.txt

Policy: codecraft.dev/security

Acknowledgments: codecraft.dev/security#thanks

Preferred-Languages: en

Expires: 2027-09-01T00:00:00Z

BOUNTY REWARDS

Critical

up to $10,000

High

up to $4,000

Medium

up to $1,000

Low

Swag + credit

§06

Security updates

A running log of notable security milestones and changes.

2026.09

Sep 18, 2026

+ Completed Q3 third-party penetration test — no high-severity findings

+ Added hardware-key requirement for all production access

2026.07

Jul 2, 2026

+ Renewed SOC 2 Type II attestation

2026.04

Apr 9, 2026

+ EU data residency available on all paid plans

− Retired legacy API keys without scopes

REPORT A VULNERABILITY

Found something? Tell us.

We acknowledge every report within 24 hours and keep you updated until it’s fixed.

security@codecraft.dev

REPORT A VULNERABILITY

Found something? Tell us.

We acknowledge every report within 24 hours and keep you updated until it’s fixed.

security@codecraft.dev

C
CodeCraft

Built for developers who’d rather ship than type boilerplate.

CODECRAFT

© 2026 CodeCraft Technologies. All rights reserved.

hello@codecraft.dev

Create a free website with Framer, the website builder loved by startups, designers and agencies.