ShipGuardeRELEASE CLEARANCE BUREAU
← BACK TO HOME
Trust

Security

Security is foundational to ShipGuarde - our agents load and execute untrusted web pages on your behalf, so we design the platform around isolation and least privilege. This page summarizes our practices.

Data protection

  • All traffic between you, our services, and our providers is encrypted in transit (TLS).
  • Screenshots and run artifacts are stored in access-controlled object storage.
  • Secrets and credentials are stored in our platform's encrypted secret store, never in source control.

Least-privilege architecture

  • The browser agent that renders untrusted pages runs as an isolated, private service and never receives database, source-control, or authentication secrets.
  • Service-to-service traffic is scoped with a shared secret and runs over a private network.
  • Our GitHub App requests only the permissions required to run checks on the repositories you authorize.

Authentication

Authentication is handled by a dedicated identity provider (Clerk), with support for multi-factor authentication. We do not store your password.

Responsible disclosure

If you believe you have found a security vulnerability, please report it to us privately at [email protected] before disclosing it publicly. We will acknowledge your report, investigate promptly, and keep you informed. We appreciate the security community’s help in keeping ShipGuarde and its users safe.

Code review checks the diff. ShipGuarde also checks the running product, so a release does not ship on the hope that nothing broke.

NO CREDIT CARD · CONNECT GITHUB IN UNDER FIVE MINUTES · CANCEL ANY TIME

FILED · SG-482 · ACME-COMMERCEEST. 2026