Cloud Infrastructure Security & Compliance
Review current practices and service boundaries. Use the security contact below to ask a question or report a concern.
HTTPS and sign-in
Customer-facing sites use HTTPS with managed certificates.
Customers sign in through GitHub OAuth. Host Little verifies the matching email address with GitHub.
Recovery boundaries
App Cloud PostgreSQL includes automatic daily encrypted backups. Current Developer and Pro plans retain them for seven days.
Owners and admins can create a separate 72-hour restore copy without overwriting the active database. The account owner can reveal a TLS verify-full connection for psql or pg_dump.
Customers manage schema, migrations, queries, data correctness, and restore validation. Point-in-time recovery and managed DBA work are not included.
Bring-your-own databases and external services remain under the recovery policies of the provider you chose.
Repository access
The GitHub App installation is separate from GitHub OAuth sign-in. Signing in does not grant Host Little access to a repository.
You control repository access through the GitHub App installation settings.
Access boundaries
Only authorized support and platform operations staff can access production systems.
App projects connect to external services through environment variables in the deployment configuration.
Regional placement
Choose from the app regions available during setup. Contact us before you buy if you have a specific placement requirement.
The Privacy Notice and Data Processing Addendum explain the data-handling terms that apply to the service.
Incident response
We investigate confirmed security incidents that affect customer data.
We follow the notification duties that apply to the incident.
Data deletion
Project deletion can remove an App Cloud runtime and its PostgreSQL database data immediately after exact confirmation.
After account cancellation, remaining production data is normally retained for up to 30 days where the product supports export or restoration, then removed subject to legal-retention needs.
Backup copies age out on their applicable retention schedule.
Data Processing Agreement
The current Data Processing Addendum is available online.
Contact us before you buy if you have a specific requirement.
Service providers
We use service providers for payment processing, account and notification email, compute, DNS, and HTTPS.
The Privacy Notice and Data Processing Addendum describe the applicable data-handling terms.
Security scope
The status page shows the public endpoint checks we run. It does not measure every customer workload or promise a service level. For formal audit or compliance requirements, contact [email protected]. We will confirm the available support path before you buy.
Security questions and reports
Report phishing, malware, spam, attacks, or harmful content through the abuse report form.