# exployt.ai Security Summary Last updated: 2026-07-08 Canonical page: https://exployt.ai/security Security contact: office@exployt.ai Standard security contact file: https://exployt.ai/.well-known/security.txt ## Short answer exployt.ai publishes security and trust facts for humans and AI crawlers. exployt is operated by exployt Software GmbH in Graz, Austria. The primary production web service runs on Microsoft Azure West Europe (Netherlands). ## Transport and storage security - HTTPS with modern TLS 1.2/1.3 is used in transit. - Azure-hosted storage uses Azure platform encryption. - Passwords are stored as bcrypt hashes. - Selected sensitive server-side fields use AES-GCM encryption and lookup hashes. - Local Windows secrets such as cached entitlement tokens, provider credentials and build/deploy credentials that use the exployt credential stores use DPAPI. - Local project databases and agent history stay on the customer's machine and are not sent to exployt cloud during ordinary desktop-app operation. - Local project database encryption is available through desktop app settings; when it is not enabled, the local SQLite database remains under the customer's own device and file-system security. ## Key and signing material Selected service secrets and signing material are managed through Azure Key Vault where configured. The desktop app keeps customer AI-provider API keys local or in the configured local/project credential store for ordinary operation. exployt cloud does not store those local AI-provider keys for ordinary desktop-app operation. ## Source code and project content exployt cloud does not collect, review or train on customer source code, file contents, local databases, agent history or project details for ordinary desktop-app operation. If the customer selects a cloud AI provider, the desktop app sends the prompts, files, snippets or context needed for the task to that provider because cloud AI cannot work without receiving task context. The customer controls that choice: direct providers, OpenRouter access to hundreds of models and local Ollama models are supported. Marketplace publishing is a separate deliberate upload for selected files and metadata the customer wants to share or sell. Support/bug-report flows show the data first and send only what the customer confirms. ## Device identifiers The desktop app may derive stable device-fingerprint signals from hardware and operating-system attributes. exployt reduces those signals to hashes/HMAC values and uses them only for account security, license integrity, known-device recognition and trial-abuse prevention, not analytics, marketing, advertising or cross-service tracking. ## Certifications As of 2026-07-08, exployt is not ISO 27001 certified and does not provide a SOC 2 Type I or Type II report. exployt is preparing the control documentation, risk assessment, access-review evidence, incident-response evidence, vendor review and management-review material needed for an ISO 27001 or SOC 2 readiness/audit process. ## DPA and subprocessors DPA requests: office@exployt.ai. exployt is preparing a public DPA package and expects to publish it in the coming weeks. Current service providers for the public website, account service, billing, email, security and optional website analytics stack include Microsoft Azure, Stripe, Resend, MaxMind offline geolocation data, and optional Google Analytics 4 / Microsoft Clarity website analytics where enabled. Customer-selected AI providers, Git services, tools, plugins, connectors, OpenRouter and local Ollama models used by the desktop app are chosen or configured by the customer and are not exployt cloud subprocessors for local project content. ## Availability and support Support requests sent to office@exployt.ai or submitted through product support/feedback forms receive an initial response within 24 hours. exployt cloud is needed for account creation, login/account management, billing, payment, subscription/license validation, Marketplace cloud actions and fresh entitlement checks. Ordinary desktop project work is local-first: the desktop app keeps a signed entitlement snapshot with a maximum 72-hour grace window, so transient server outages do not immediately remove access to subscription-locked features. If an exployt cloud outage occurs, the operational commitment is to restore the account/subscription service before that 72-hour grace window expires. This public commitment does not create service credits unless a separate written enterprise agreement says so.