Trust center

Trust & Security

Direct answers for IT, legal, security and AI-based vendor reviews. This page is written to be readable by humans and by crawlers that need clear facts without marketing language.

Last updated: July 8, 2026

Quick Answers

Legal operator

exployt is operated by exployt Software GmbH, Lange Gasse 30, 8010 Graz, Austria. Commercial register: FN 675480d, Landesgericht fuer ZRS Graz. VAT ID: ATU83180825. Managing director: Michael Martin Schoeggl.

Primary hosting region

The core exployt web service is hosted on Microsoft Azure in West Europe (Netherlands). Optional third-party services may process data in other regions under their own terms and transfer safeguards.

Source code and project data

exployt cloud does not collect, review, or train on your source code, file contents, local project databases, local agent history, or private project details during ordinary desktop-app operation. Those materials stay on your machine unless you deliberately take a separate action: you choose a cloud AI provider and send task context to that provider, you publish selected files and metadata as a Marketplace item for sharing or sale, or you submit a support/bug report after previewing and confirming exactly what will be sent. Marketplace items can include integrations, modules, standalone apps, settings sets, workflows, connector packages, or reusable assets; you choose what goes into the package, and we recommend minimization plus obfuscation where appropriate.

Certifications

exployt is not currently ISO 27001 certified and does not currently provide a SOC 2 Type I or Type II report. We are preparing the control and evidence work needed for external audits.

Security Controls

Encryption in transit and at rest

Traffic between the browser, desktop app and exployt services uses HTTPS with modern TLS. TLS 1.2/1.3 is the correct industry-standard transport protection for web traffic; stronger security comes from using current TLS versions, managed certificates, platform hardening, and separate encryption for stored sensitive data rather than inventing a custom transport cipher. Azure-hosted production storage and databases use platform encryption at rest. Passwords are stored as bcrypt password hashes, not reversible encryption. Selected abuse-prevention personal data is encrypted with AES-GCM before storage, and selected lookup values are stored as hashes.

Local secrets and local databases

AI-provider API keys are not stored in exployt cloud for ordinary desktop-app operation. Local provider credentials, cached entitlement tokens and build/deploy secrets that use the exployt credential stores are protected with Windows DPAPI under the current Windows user account. Local project databases and agent history stay on your machine and are not sent to exployt cloud. Local project databases can be encrypted from the desktop app's encryption settings; when you do not enable that option, the SQLite database remains under your own device and file-system security.

Key management

Production secrets should be supplied through managed hosting configuration and Azure Key Vault references where applicable. Seat entitlement tokens are signed with ES256 through Azure Key Vault. Hardware identifiers used for seat binding and abuse prevention are reduced to server-side HMAC-SHA256 values with a server-side salt before they are stored.

Access controls

Accounts require verified credentials and support two-factor authentication. Internal cloud endpoints are role- and token-gated. Customer-selected AI providers and third-party tools remain under the customer's own provider accounts and provider terms.

Privacy, AI and Data Flow

What exployt cloud processes

exployt cloud processes concrete service data categories: account and authentication data, billing and payment state, subscription and license state, security and fraud-prevention signals, support and feedback records you submit, and consented website analytics. We do not collect Big Data from your projects, harvest source files, or build datasets from your code, local databases, or agent history.

AI providers

exployt is an orchestration layer, not the AI model provider. exployt cloud does not collect your source code for training, review, or storage. If you select a cloud AI provider, the desktop app sends the prompts, files, snippets, or context needed for the task to that provider because cloud AI cannot work without receiving task context. You control that choice: exployt supports direct provider connections, OpenRouter access to hundreds of models, and local models through Ollama for sensitive work where project content should not leave your machine. Provider use is explicit and governed by the provider account and terms you configure.

Marketplace uploads and confirmed support reports

If you intentionally publish an item through the exployt Marketplace, the files and metadata you upload for that item are transmitted so the item can be reviewed, hosted, shared, sold or delivered to buyers. For Marketplace items that contain code, connector packages, integration modules or reusable project assets, we recommend minimizing the package and using obfuscation where appropriate; exployt is designed to support that workflow. For support, feedback and bug reports, the product flow shows you the data to be submitted before sending, asks for your confirmation, and sends only the data you approve.

Desktop app known-device and seat checks

For known-device, trial-abuse and seat-entitlement checks, the desktop app may send stable device fingerprint inputs to the exployt API. The API stores reduced HMAC/hash values rather than the raw identifiers where the value is used for matching. These signals are used for account security, abuse prevention and license enforcement, not advertising or cross-service tracking.

DPA and Subprocessors

Business customers can request a Data Processing Agreement (DPA) and current security documentation via office@exployt.ai. We are preparing a public DPA package and expect to publish it in the coming weeks. Where a controller/processor relationship requires a DPA, the business customer should not rely on an unsigned public page alone; the signed DPA or separate written agreement controls.

Microsoft AzureHosting, storage, databases and infrastructure. Primary region: West Europe (Netherlands).
StripePayment processing, invoices, subscriptions and billing workflows.
ResendTransactional email such as verification, password reset, account and subscription emails.
MaxMindOffline IP geolocation database for security and abuse prevention. Runtime user data is not sent to MaxMind for these lookups.
Google Analytics 4Optional website analytics only after consent.
Microsoft ClarityOptional website behavior analytics only after consent.

This list covers exployt's public website, account service, billing, email, security, and optional website analytics stack. The desktop app can also use tools, plugins, connectors, Git services, AI providers, OpenRouter, or local Ollama models that you explicitly configure or invoke. Those are under your control and are not exployt cloud subprocessors for local project content.

Availability, Export and Exit

SLA and support

Support requests sent to office@exployt.ai or submitted through product support/feedback forms receive an initial response within 24 hours. exployt cloud is needed for account creation, login/account management, billing, payment, subscription/license validation, Marketplace cloud actions, and fresh entitlement checks. Ordinary desktop project work is local-first: the desktop app keeps a signed entitlement snapshot with a maximum 72-hour grace window, so transient server outages do not immediately remove access to subscription-locked features. If an exployt cloud outage occurs, our operational commitment is to restore the account/subscription service before that 72-hour grace window expires. This public commitment does not create service credits unless a separate written enterprise agreement says so.

Data export and deletion

Account deletion is available from the account settings and uses an email confirmation step. GDPR access, portability and deletion requests can be sent to office@exployt.ai. Local project files, source code, agent history, local credentials, and the local project database remain under your control. The project database is a SQLite database stored under the project's .exployt folder; when local database encryption is not enabled, it can be inspected or exported with ordinary SQLite-compatible tools. exployt also provides export/import flows for workflows, settings sets, and many configuration assets such as agent/workflow settings.

Exit strategy

The practical exit path is: cancel the subscription, retain or export local project data and configuration assets, request a GDPR account export where needed, and delete the cloud account when no longer required. The Terms do not restrict you from using your own local project data with other software. Billing, tax, fraud-prevention and security logs may be retained for legally required or security-necessary periods.

Certification Roadmap

We do not currently claim ISO 27001 certification, SOC 2 Type I, SOC 2 Type II or an equivalent third-party attestation. The correct current status is: security controls exist, documentation is being consolidated, and formal audit readiness is planned.

Planned work includes ISMS scope definition, risk assessment, policies, asset inventory, access review evidence, incident-response evidence, vendor/subprocessor review, internal audit, management review, and then an external ISO 27001 or SOC 2 readiness/audit engagement.

Machine-readable Resources