Skip to content
Host Little logo markHost Little

Platform security

Review account access, data recovery, infrastructure placement, and your responsibilities.

HTTPS and sign-in

Customer-facing sites use HTTPS with managed certificates.

Customers sign in through GitHub OAuth or a verified email sign-in link. Repository access remains a separate GitHub App permission.

Recovery boundaries

Database Hosting uses encrypted logical backups and isolated restore paths so restore work does not overwrite the primary database.

The product supports bounded Workbench queries and owner-only trusted-TLS connection reveal.

Customers manage schema, migrations, queries, data correctness, and restore validation. Point-in-time recovery and managed DBA work are not included.

Bring-your-own databases and external services remain under the recovery policies of the provider you chose.

Repository access

The GitHub App installation is separate from GitHub OAuth sign-in. Signing in does not grant Host Little access to a repository.

You control repository access through the GitHub App installation settings.

Access boundaries

Only authorized support and platform operations staff can access production systems.

App projects connect to external services through environment variables in the deployment configuration.

Regional placement

Apps run in US East (N. Virginia), and managed Postgres runs in New York. Contact us before purchase if you need a specific placement.

The Privacy Notice and Data Processing Addendum explain the data-handling terms that apply to the service.

Incident response

We investigate confirmed security incidents that affect customer data.

We follow the notification duties that apply to the incident.

Data deletion

Project deletion can remove an App Cloud runtime and any attached database data immediately after exact confirmation when Database Hosting is enabled for that workspace.

After account cancellation, remaining production data is normally retained for up to 30 days where the product supports export or restoration, then removed subject to legal-retention needs.

Backup copies age out on their applicable retention schedule.

Data Processing Agreement

The current Data Processing Addendum is available online.

Contact us before you buy if you have a specific requirement.

Service providers

We use service providers for payment processing, account and notification email, compute, DNS, and HTTPS.

The Privacy Notice and Data Processing Addendum describe the applicable data-handling terms.

Security scope

The status page shows the public endpoint checks we run. It does not measure every customer workload or promise a service level. For formal audit or compliance requirements, contact [email protected]. We will confirm the available support path before you buy.

Security questions and reports

[email protected]

Report phishing, malware, spam, attacks, or harmful content through the abuse report form.