Skip to content
Launching Oct 10 — OpenPush is free forever to 1M MAU per app, every feature included. Get early access →
ProductJourneysLive ActivitiesPricingCompareDocsChangelogMigrate from OneSignalSign in
openpush.ai · Trust

Trust center.

What a security review actually needs: what is in place, what is not yet, what you can verify without trusting us — and every document, public, with nobody to ask for access.

Last updated 9 August 2026 · Operated by SuperTuned Inc

Nothing on this page is aspirational. Where a certification exists, it is named. Where it does not, the row says so and points at what exists instead. When something lands, this page changes — not before. Checks run against the rendered site on every deploy to keep it that way.

Certifications and attestations

Most trust pages open with a badge wall. Ours opens with the truth: we are early, and we would rather tell you where we stand than rent a seal.

What you can verify without trusting us

  • Your notifications leave on your own APNs and FCM credentials, and there is no delivery network of ours in between to intercept them. There is nothing of ours in the delivery path to compromise.
  • Open devtools on any page here: nothing loads from a third-party origin. No analytics, no trackers, no outside CDN, no font hosts.
  • The subprocessor list is dated and deliberately indexable. A list hidden from search engines is a list you are not meant to check.
  • /.well-known/security.txt is at the standard path and names the same security mailbox as this page.
  • Delivery metrics report what actually happened at each step, rather than calling “the provider accepted it” a delivery.

The full argument for why the mechanism is the trust story is on the about page.

Controls in place today

  • Per-app push credentials are encrypted with AES-256-GCM and bound to their own row.
  • TLS end to end, with HSTS, and security headers on every response.
  • Role-based access with an exhaustive route-permission test.
  • A change-control record: an automated check suite runs on every push before it can deploy — including the checks that keep this page honest.
  • The waitlist database denies by default. Row-level security is on with no policies; the public key can read nothing at all.
  • Secrets live in the deployment environment, never in the repository.

The full account — including what is not in place — is on the security page, which says “no” in plain words where the answer is no.

How customer data is handled

  • Advertising identifiers, precise location and email addresses are off by default, per app — and turning one off erases what was collected under it.
  • IP storage is a setting (OP_IP_STORAGE): full, truncated, or not at all.
  • Export is point-in-time and snapshot-isolated, and states its mode — the data export commitment is a page, not a promise in a sales deck.
  • Retention periods are published on the limits page, not buried in prose.
  • Delivery necessarily hands the token and payload to Apple or Google — that is what sending a push means, and both are named on the subprocessor list.

Subprocessors, and how you hear about changes

The subprocessor list is short, dated, and public. We give 30 days' notice before a new subprocessor starts processing customer data, the notification list is one we operate ourselves, and under the DPA you may object within that window. To join the notice list, write to privacy@openpush.ai.

Availability

There is still no availability percentage on this page, and there will not be one until it can be measured over a meaningful period. What does exist is the thing that makes a percentage checkable later — a public status page the server generates about itself: deployed commit, database engine and migration count, queue depth, and provider readiness, with the same figures as JSON at /healthz.

The reason to trust it is that it reports bad news. At the time of writing it says APNs is not ready — which is true; no APNs key has been uploaded, so iOS sends cannot go out at all. A status page that can only say "OK" is decoration, and the pre-launch gate in this repository asserts that this one still carries the vocabulary to say otherwise.

Reporting a vulnerability

Email security@openpush.ai. We aim to acknowledge within two business days, and the vulnerability disclosure policy sets out the safe-harbour terms in full — it is one of the pages on this site that is already in force.

Documents

Everything below is public. Nothing is gated behind an access request, an NDA, or a sales call — if a policy applies to you, you can read it before you ever talk to us.

Ask us the hard questions

If your procurement process needs SOC 2, a pentest report, or a BAA, talk to us early rather than late — we will tell you honestly where we are, answer your questionnaire directly, and not waste your time. Write to security@openpush.ai for security, or hello@openpush.ai for everything else.

Who operates this service

SuperTuned Inc
1 Sansome Street, San Francisco, CA 94104, USA

Privacy: privacy@openpush.ai · Legal: legal@openpush.ai · Security: security@openpush.ai