Trust center.
What a security review actually needs: what is in place, what is not yet, what you can verify without trusting us — and every document, public, with nobody to ask for access.
Nothing on this page is aspirational. Where a certification exists, it is named. Where it does not, the row says so and points at what exists instead. When something lands, this page changes — not before. Checks run against the rendered site on every deploy to keep it that way.
Certifications and attestations
Most trust pages open with a badge wall. Ours opens with the truth: we are early, and we would rather tell you where we stand than rent a seal.
| Framework | Where we stand | What exists instead |
|---|---|---|
| SOC 2 | Not held. | We answer security questionnaires directly, in writing, from the people who built the system — email security@openpush.ai. The controls below are the inventory a report would summarise. |
| ISO 27001 | Not held. | Same answer: ask us, and we reply in writing rather than with a marketing PDF. |
| Penetration test | Not commissioned yet. | The vulnerability disclosure policy and its safe harbour are live today, and researchers are invited. |
| GDPR | DPA with EU Standard Contractual Clauses, published. | Read the DPA — including the plain statement that we are not currently suitable if you need the UK IDTA, the Swiss addendum, or DPF. |
| HIPAA | We cannot sign a BAA. | If your notifications would carry PHI, OpenPush is not the right home for it today. |
| Bug bounty | No paid programme. | A fast human response, credit if you want it, and safe harbour in writing. |
What you can verify without trusting us
- Your notifications leave on your own APNs and FCM credentials, and there is no delivery network of ours in between to intercept them. There is nothing of ours in the delivery path to compromise.
- Open devtools on any page here: nothing loads from a third-party origin. No analytics, no trackers, no outside CDN, no font hosts.
- The subprocessor list is dated and deliberately indexable. A list hidden from search engines is a list you are not meant to check.
- /.well-known/security.txt is at the standard path and names the same security mailbox as this page.
- Delivery metrics report what actually happened at each step, rather than calling “the provider accepted it” a delivery.
The full argument for why the mechanism is the trust story is on the about page.
Controls in place today
- Per-app push credentials are encrypted with AES-256-GCM and bound to their own row.
- TLS end to end, with HSTS, and security headers on every response.
- Role-based access with an exhaustive route-permission test.
- A change-control record: an automated check suite runs on every push before it can deploy — including the checks that keep this page honest.
- The waitlist database denies by default. Row-level security is on with no policies; the public key can read nothing at all.
- Secrets live in the deployment environment, never in the repository.
The full account — including what is not in place — is on the security page, which says “no” in plain words where the answer is no.
How customer data is handled
- Advertising identifiers, precise location and email addresses are off by default, per app — and turning one off erases what was collected under it.
- IP storage is a setting (
OP_IP_STORAGE): full, truncated, or not at all. - Export is point-in-time and snapshot-isolated, and states its mode — the data export commitment is a page, not a promise in a sales deck.
- Retention periods are published on the limits page, not buried in prose.
- Delivery necessarily hands the token and payload to Apple or Google — that is what sending a push means, and both are named on the subprocessor list.
Subprocessors, and how you hear about changes
The subprocessor list is short, dated, and public. We give 30 days' notice before a new subprocessor starts processing customer data, the notification list is one we operate ourselves, and under the DPA you may object within that window. To join the notice list, write to privacy@openpush.ai.
Availability
There is still no availability percentage on this page, and there will not be one until it can be measured over a meaningful period. What does exist is the thing that makes a percentage checkable later — a public status page the server generates about itself: deployed commit, database engine and migration count, queue depth, and provider readiness, with the same figures as JSON at /healthz.
The reason to trust it is that it reports bad news. At the time of writing it says APNs is not ready — which is true; no APNs key has been uploaded, so iOS sends cannot go out at all. A status page that can only say "OK" is decoration, and the pre-launch gate in this repository asserts that this one still carries the vocabulary to say otherwise.
Reporting a vulnerability
Email security@openpush.ai. We aim to acknowledge within two business days, and the vulnerability disclosure policy sets out the safe-harbour terms in full — it is one of the pages on this site that is already in force.
Documents
Everything below is public. Nothing is gated behind an access request, an NDA, or a sales call — if a policy applies to you, you can read it before you ever talk to us.
Ask us the hard questions
If your procurement process needs SOC 2, a pentest report, or a BAA, talk to us early rather than late — we will tell you honestly where we are, answer your questionnaire directly, and not waste your time. Write to security@openpush.ai for security, or hello@openpush.ai for everything else.
SuperTuned Inc
1 Sansome Street, San Francisco, CA 94104, USA
Privacy: privacy@openpush.ai · Legal: legal@openpush.ai · Security: security@openpush.ai