Security
What protects your app, and who can reach it.
Where your data lives, how secrets are handled, and what our own operators can and cannot do.
Data
Where it lives, how it is guarded.
The measures in place today.
-
In the EU
Your application and its data run on servers in Frankfurt. Our infrastructure provider is Amazon Web Services (Lightsail).
-
HTTPS only
Visitors reach your app over HTTPS; plain HTTP is only redirected. The certificate is issued and renewed automatically.
-
Careful server access
The platform manages servers over SSH with short-lived credentials that exist only in memory for the length of the session, and it checks each server’s host key before it sends a command.
-
Secrets, handled
The passwords and keys of your stack are generated for it and live in its configuration on the server. A secret you type when buying, such as an admin token, is encrypted in our database until the first deployment and then erased. Secrets are stripped from the operation logs we keep.
-
Cards stay with the provider
Payments run through our payment provider, Paddle. We receive the status of your subscription, never your card number.
-
Your dashboard is yours alone
What you see in the dashboard is limited to your workspace in the database query itself, not only by checks in application code.
Operators
Who can do what, and what is written down.
Running your app means some people on our side can reach it. This is what that access is, and where it stops.
What operators can do
Operators run the servers your app lives on. From the admin screens they can start, stop, upgrade and delete a deployment, and they read its operation log.
An administrator can open the dashboard as you (“Sign in as”) to see what you see, for example to help with a problem.
Some applications need a service administrator that we create, so the dashboard can hand you your own login; Umami’s is called poof-service. It stays visible in the application’s user list.
What is closed to them
While signed in as you, an operator cannot start a checkout, pay, change your card, open the billing portal or create the application’s administrator login: those requests are refused.
“Sign in as” works only for an administrator, never on another administrator’s account or on one’s own, and it needs a valid form token, so a crafted link cannot start it.
The operation log an operator reads, with every command run on your server, has secrets stripped from it before it is written.
Written down. Every “Sign in as” is recorded when it starts and when it ends: who, as whom, when, from which address. So are granting or removing administrator rights, suspending accounts and changing settings. Administrators read this audit log; you cannot read it yourself yet.