Skip to content

Trust center

Show your work.

What we run, who processes data on our behalf, and how we prove this site is what we claim it is.

Mozilla Observatory: A+SSL Labs: A+securityheaders.com: A+Lighthouse ≥ 95WCAG 2.2 AA

Sub-processors

VendorPurposeLocationTransfer mechanism
CloudflareDNS, edge TLS, DDoS protection, WAFGlobal, with EU/US presenceSCCs in place
HetznerPrimary application hostingFalkenstein, Germany (EU)GDPR — no transfer
Listmonk (self-hosted)Newsletter deliveryEUGDPR — no transfer
Plausible (self-hosted)Cookieless analyticsEUGDPR — no transfer
Backblaze B2Encrypted off-site backupsEU regionSCCs in place

Audit & assurance

  • External pentest: scheduled annually; latest summary published here.
  • Dependency audit: weekly via Dependabot + Renovate.
  • CodeQL: every pull request.
  • SBOM (CycloneDX): published per release at /trust/sbom.json.
  • Backup restore test: quarterly.

Incident history

No material incidents to date. Post-mortems for any material incident will be published within 30 days on our writing feed.

Trust center · Reseni Labs