Security
Last updated: September 20, 2026
Encryption
All data is encrypted in transit (TLS 1.2+) and at rest.
Isolation
Each hosted project runs on its own dedicated Postgres instance, not a shared multi-tenant database.
Open source
The instancez runtime is open source under Apache-2.0, so its code is publicly auditable rather than a black box.
Access control
Row-level security policies you define control who can read or write your application data. Enterprise plans add SSO (SAML/OIDC) for your whole team.
Self-hosting
If you'd rather not depend on our infrastructure at all, self-host the same runtime binary on your own servers with full control over data residency.
Responsible disclosure
Found a vulnerability? Email [email protected] with details. We'll acknowledge within 2 business days and won't pursue legal action against good-faith security research.