WPBit.io
Log inStart free trial
LEGAL

Security

How the platform is built and operated, and how to report a vulnerability.

Updated Jul 02, 2026

Each site runs a small signed connector rather than storing your admin credentials. Requests are authenticated with an asymmetric key pair created on your site, rotated every 30 days, and revocable from the dashboard. A revoked key cannot be replayed.

All traffic uses TLS 1.3. Backups and snapshots are encrypted with AES-256 before leaving your server, with keys held in a managed KMS separate from the storage account.

Production access requires SSO with hardware security keys, is scoped by role, expires automatically, and is logged. Support engineers cannot read customer backup contents; access to a workspace for debugging requires an in-app approval from you.

The platform runs multi-AZ with automated failover. Uptime probes run from 12 regions independently of the control plane, so monitoring keeps working during our own incidents. Live status and history are published at status.wpbit.io.

Annual third-party penetration tests, continuous dependency scanning, and internal review of every change touching authentication or backup paths. Test summaries are available under NDA.

Report findings to security@wpbit.io, optionally PGP-encrypted. We acknowledge within one business day, aim to triage within three, and credit reporters who ask to be named. We do not pursue legal action against good-faith research that respects customer data.

GDPR-aligned processing with an EU-first data residency default, SOC 2 Type II in progress with a target of Q4 2026, and a signed DPA available to every paid workspace.

Questions about this document? Email legal@wpbit.io.