Dependency Firewall offer: 50% off your base fee for 3 months + €100 usage credit.Start trialSee what’s new

Security

Bytesafe runs as managed SaaS in the EU, on Scaleway in France by default. On Enterprise it can also run in your own cloud account, in your data center or through a partner we arrange with you.

Where it runs

Most teams use the managed SaaS. On-premise and partner-operated deployments keep Bytesafe out of the data path entirely.

Managed SaaS

Hosted by: Bytesafe (Scaleway, France, default; AWS in the EU, optional on request)

Data location: EU

Operated by: Bytesafe

Ready to use. No infrastructure to provision or maintain.

BYO Cloud

Hosted by: Your cloud account

Data location: Your chosen region

Operated by: You

Full control over cloud account and region.

On-Premise

Hosted by: Your data center

Data location: Your data center

Operated by: You

Runs inside your network. No data leaves your environment.

Partner (MSP)

Hosted by: Arranged with a partner

Data location: Partner-defined

Operated by: Partner, arranged with Bitfront

Enterprise only. Scoped with us case by case.

How we protect your data

Data and encryption

The managed SaaS runs on Scaleway in France by default. AWS in the EU is available on request. We store and process data in the EU.

Access

Access to production is tied to identity and limited to what each role needs.

  • Sign in with Google, Microsoft or GitHub, or with SSO through your own identity provider. SSO per plan is on the pricing pages
  • MFA enforced for production and administrative access wherever the underlying system supports it
  • Role-based, least-privilege access
  • Access rights reviewed periodically and revoked within 48 hours of offboarding
  • Network segmentation between development and production
  • Threat detection and edge protection on all production infrastructure

Development

Security review starts at design and runs through code review and CI.

  • Security review at the design stage for new features
  • Code review for all significant changes
  • Static analysis and dependency scanning in CI
  • Our own pipelines install through Dependency Firewall

Vulnerability management

Findings are triaged by severity, and fixes are tracked against internal SLA targets.

  • Triage by exploitability and exposure in the application
  • Compensating controls where an upstream fix is not yet available
  • Audit logging across all production infrastructure

Responsible disclosure

Found a vulnerability in Bytesafe? Email security@bytesafe.dev. We work with you on a fix before anything is disclosed publicly.

  • Make a good faith effort to avoid violating privacy, destroying data or disrupting the service
  • Only interact with accounts you own or have explicit permission to test

Incident response

Report security issues to security@bytesafe.dev. Incidents that affect customers are posted on the public status page.

  • Service availability monitored by a third party
  • Personal data breaches notified to you within 72 hours, in line with GDPR Article 33
  • Custom SLA available on Enterprise

Who runs it

Bytesafe is built and operated by Bitfront AB, incorporated in Sweden. We have built dependency security tools since 2018. About Bytesafe

Legal documents: Data Processing Agreement, subprocessors and privacy policy.

Questions

Where is data stored in the managed SaaS deployment?
On Scaleway infrastructure in France by default. AWS in the EU is available on request. We store and process it within the EU. Two subprocessors, Neon and Sinch Email, are US-established companies that process in the EU region we selected, covered by Standard Contractual Clauses. Full detail on our Subprocessors page.
Can we run Bytesafe in our own environment?
Yes. On-premise deployment is available. No Bytesafe sub-processors are involved in the data plane for on-premise deployments. Contact us to discuss requirements.
Who has access to our data in the SaaS deployment?
Bytesafe operations staff, under GDPR-compliant data processing terms. Production access requires SSO and MFA. A full Data Processing Agreement is available and can be countersigned on request.
What are your breach notification timelines?
We notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach. As processor our duty under Article 33(2) GDPR is to notify you, not the supervisory authority, which retains its own Article 33(1) obligations toward yours.

SaaS in the EU or on your own servers

Book a call to go through SaaS, on-premise and partner deployment with an engineer, and how each fits your security requirements.

Book a Demo