# exployt.ai Trust, Security and Compliance Facts Last updated: 2026-07-08 Canonical human page: https://exployt.ai/security Canonical LLM overview: https://exployt.ai/llms.txt This file is written for vendor reviews, security reviews and AI crawlers. It intentionally repeats the public Trust & Security, FAQ, Privacy and Terms facts in plain text. ## Company identity exployt.ai is operated by exployt Software GmbH. Address: Merangasse 53/3, 8010 Graz, Austria. Commercial register: FN 675480d, Landesgericht fuer ZRS Graz. VAT ID: ATU83180825. Managing director: Michael Martin Schoeggl. Contact: office@exployt.ai. ## Hosting and data residency The primary production web service is hosted on Microsoft Azure in the West Europe region (Netherlands). Customer source code, local project files, local project databases, local agent history and local AI-provider API keys stay on the customer's machine during ordinary desktop-app operation. If the customer intentionally publishes an item to the exployt Marketplace, selected files and metadata for that item must be uploaded to exployt servers so the item can be reviewed, hosted, shared, sold and delivered to other users. Marketplace items can include integrations, modules, standalone apps, settings sets, workflows, connector packages or other reusable assets; the customer chooses what to include, and exployt recommends minimization plus obfuscation where appropriate. For support, feedback and bug reports, the app or website shows the data to be submitted before sending and submits only what the customer confirms. ## Security controls Traffic between the app, website and servers uses HTTPS with modern TLS 1.2/1.3. Azure-hosted storage relies on Azure platform encryption. Passwords are stored as bcrypt hashes, not plaintext. Selected sensitive server-side fields use AES-GCM encryption and lookup hashes. Local Windows secrets such as cached entitlement tokens, provider credentials and build/deploy credentials that use the exployt credential stores use DPAPI. Local project databases and agent history stay on the customer's machine. Local project database encryption is available in the desktop app settings; when it is not enabled, the local SQLite database remains under the customer's own device and file-system security. ## AI providers and source code exployt cloud does not collect, review or train on source code, file contents, local databases, agent history or project details during ordinary desktop-app operation. If the customer selects a cloud AI provider, the desktop app sends the prompts, files, snippets or context needed for the task to that provider because cloud AI cannot work without receiving task context. The customer controls that choice: exployt supports direct provider connections, OpenRouter access to hundreds of models and local models through Ollama for sensitive work where project content should not leave the machine. Marketplace publishing is a separate deliberate upload, and support/bug-report flows show the data first and send only what the customer confirms. ## Certifications As of 2026-07-08, exployt is not ISO 27001 certified and does not provide a SOC 2 Type I or Type II report. exployt is preparing the control documentation, risk assessment, access-review evidence, incident-response evidence, vendor review and management-review material needed for an ISO 27001 or SOC 2 readiness/audit process. ## DPA and subprocessors Business and enterprise customers can request a Data Processing Agreement by contacting office@exployt.ai. exployt is preparing a public DPA package and expects to publish it in the coming weeks. Current service providers for the public website, account service, billing, email, security and optional website analytics stack include Microsoft Azure, Stripe, Resend, MaxMind offline geolocation data, and optional Google Analytics 4 / Microsoft Clarity website analytics where enabled. Customer-selected AI providers, Git services, tools, plugins, connectors, OpenRouter and local Ollama models used by the desktop app are chosen or configured by the customer and are not exployt cloud subprocessors for local project content. ## SLA and support Support requests sent to office@exployt.ai or submitted through product support/feedback forms receive an initial response within 24 hours. exployt cloud is needed for account creation, login/account management, billing, payment, subscription/license validation, Marketplace cloud actions and fresh entitlement checks. Ordinary desktop project work is local-first: the desktop app keeps a signed entitlement snapshot with a maximum 72-hour grace window, so transient server outages do not immediately remove access to subscription-locked features. If an exployt cloud outage occurs, the operational commitment is to restore the account/subscription service before that 72-hour grace window expires. This public commitment does not create service credits unless a separate written enterprise agreement says so. ## Export, deletion and exit Local project files, source code, agent history, local credentials and the local project database remain under customer control. The project database is a local SQLite database stored under the project's .exployt folder; when local database encryption is not enabled, it can be inspected or exported with ordinary SQLite-compatible tools. exployt also provides export/import flows for workflows, settings sets and many configuration assets such as agent/workflow settings. The Terms do not restrict customers from using their own local project data with other software. For cloud account data and personal data processed by exployt, customers may request access, deletion, restriction or portability under the Privacy Policy and applicable law. Some records must be retained for legal, tax, accounting, fraud-prevention, dispute or security reasons. ## Security contact Security reports: office@exployt.ai. Machine-readable contact: https://exployt.ai/.well-known/security.txt.