Trust center
Current security and data handling information for evaluating Mainbrella.
Last reviewed:
Security overview
Linux workloads run on Cloudflare Containers. Mainbrella checks account ownership and exact container generations, bounds execution, and uses revocable hashed API keys and secure browser sessions. See the security overview for implemented controls and isolation details.
Mainbrella does not currently claim SOC 2 or ISO 27001 certification or an independent penetration-test attestation. Infrastructure provider certifications are not Mainbrella certifications.
Infrastructure providers and subprocessors
Cloudflare provides website, API, compute, and database infrastructure. Google provides sign-in; Stripe provides billing. The provider and subprocessor list describes purposes, data categories, and processing locations.
Data handling and encryption
The public website and API use HTTPS. Session tokens, API keys, and SSH access tokens are stored as hashes; full card details are handled by Stripe. No customer-managed encryption keys or Mainbrella-specific encryption-at-rest attestation is offered.
Container files are ephemeral and lost after stop. Account and billing records, owned image records, and build logs have separate retention needs. Keep independent backups and avoid unnecessary personal data and secrets. Outbound internet access is enabled; you control the services your workload contacts.
Mainbrella does not guarantee a data residency region. See the Privacy Policy for retention, deletion requests, and international processing.
Vulnerability reporting
Report security issues to security@mainbrella.com. Read the vulnerability disclosure policy for scope and permitted testing.
Business continuity and service commitments
Mainbrella depends on Cloudflare for infrastructure and on Google and Stripe for sign-in and billing. No recovery-time or recovery-point objective is committed, and stopped containers cannot be restored. Export needed outputs and keep workload inputs outside the container.
Service status publishes dated manual observations and incident history. Self-service plans have no uptime SLA, guaranteed support response time, or automatic service credits; see the availability terms. Benchmarks describe observations, not service commitments.
DPA availability
No standard Mainbrella Data Processing Agreement is currently published or offered through self-service checkout. Contact support@mainbrella.com before submitting personal data that requires a DPA or special safeguards. An inquiry does not establish that Mainbrella can meet those requirements; any supported use requires prior written agreement.
Provider DPAs do not create an agreement between you and Mainbrella. The Privacy Policy and Terms of Service describe the current service.
Security and procurement questions
Email security@mainbrella.com for security questions, or use Contact for deployment, privacy, and contract inquiries.