Trust & Posture
Security at Launchverse
How we protect your code, your secrets and your users' data. Honest about what we do, honest about what we don't.
Encryption in transit
launchverse.app, dashboard APIs, deployed apps and the engine control plane is served over TLS 1.3. HSTS is enforced on the marketing site, and Cloudflare sits in front of every public endpoint. SSH connections to BYOS hosts use OpenSSH defaults (curve25519, ChaCha20-Poly1305).Authentication & RBAC
Tenant isolation
Secrets handling
(project_id, environment_id, key) so a non-default environment cannot leak production secrets. Secrets are never written to logs. Public-facing build logs strip known secret patterns (API keys, JWT-shaped strings) before rendering.Data location
Auditability
Webhook integrity & replay protection
Capacity admission control
Cron & service-role hardening
Authorization header in constant time. The Postgres functions they call are SECURITY DEFINER and granted only to service_role, so a leaked anon key cannot trigger them.Data retention
Subprocessors
Compliance posture
Launchverse is a Nigerian company and we operate against the Nigerian Data Protection Regulation (NDPR) and the GDPR as applicable for EU-resident users. We do not currently hold a SOC 2 attestation; this is on our roadmap for 2027 once we onboard our first enterprise cohort.
Customers handling regulated data (financial services, health, public sector) are served best by our BYOS Enterprise plan— we manage the control plane while your data stays on infrastructure you control, in the jurisdiction you choose.
We sign Data Processing Agreements (DPAs) on request for paid plans. Email [email protected] and we'll route a draft within two business days.
Responsible disclosure
Found a vulnerability? Email [email protected] with a description, reproduction steps and the impact you assess. We commit to:
- Acknowledge receipt within 2 business days.
- Provide an initial triage and severity assessment within 5 business days.
- Coordinate a fix and public disclosure within 90 days, or sooner if a fix lands earlier.
- Credit you in the changelog if you want public attribution.
- Not pursue legal action against good-faith security research that respects user data and avoids service disruption.
We don't currently run a paid bounty programme. We do send Launchverse swag and credit-on-platform for valid reports.
Have a security question we haven't answered? [email protected].
See also: Privacy Policy · Terms of Service · Changelog