
Security Principles
We understand that protecting your customer's data is vital for you. It's just as important for us. We're tired of "free" products which actually make money by selling your data.Bugfender is fully committed to safeguarding the data we're handling for you. Here is how we do it:
Already Trusted by Thousands
Here is how we do it
Your Customer's Data is Yours
… and we operate by this principle. We don't use your customer's data, we don't sell it to third parties, and we dont target your customers with ads, tracker cookies or anything like it. Period.
User Account Protection
Team members' passwords are securely stored using a password-based key derivation function, making them unguessable by staff or intruders.
We offer two-factor authentication via time-based one-time passwords (Google Authenticator, Authy), FIDO U2F Security Keys (YubiKey, Krypton), and SMS phone validation as a fallback.
An audit log tracks recent account and team activity. If customer support accesses your account to assist you, their actions will be logged for transparency. Our staff always uses two-factor authentication for maximum security, even if you do not.
Data Protection
All network communications involving your logs are protected with TLS 1.3 and strong cipher algorithms. For compatibility, TLS 1.2 is also accepted. Your data is always authenticated and encrypted in transit and at rest.
Our staff uses two-factor authentication to access your data. Only select customer support and operations employees have access, and they receive security training.
We operate datacenters in multiple, distant locations EU locations for quick recovery. Custom datacenters
are available upon request.
Contact us for more information.
Compliance
Bugfender complies with GDPR and can process customer personal data under GDPR. You can sign a Data Protection Agreement with us for standard data categories. This includes support for data access, rectification, erasure, expiration, portability, export, and breach notification.
ISO Certification
Bugfender is ISO 27001 certified. Our code follows a Secure Development Life Cycle, with manual and automated reviews, and penetration tests. We have an incident response process, perform employee background checks, training, and supplier vetting. We process data at ISO 27001-certified data centers in the EU, ensuring legal, physical, and logical security, regular audits, and staff training. Your financial information, such as credit card data, is securely managed by a third-party PCI-certified supplier.
Highly sensitive workloads
Bugfender On-Premises or Private Instance editions support PCI and
HIPAA-compliant workloads or those requiring data locality.
Enterprise customers can sign custom contracts if specific language is needed.
Contact us for more information.
Testimonials
What Do Our Customers Say?
Bugfender is helping thousands of developers all over the world to release superb, bug-free applications.