Offer now: 50% off your base fee for 3 months + €100 usage credit.Start trialSee what’s new

Security

Bytesafe is available as managed SaaS on Scaleway in France by default, with AWS in the EU on request, in your own cloud account, on-premise in your data center, or, for Enterprise, through a partner deployment we arrange with you. You choose where it runs.

Deployment options

Most teams use managed SaaS. For stricter data residency or compliance requirements, on-premise deployment is available, and Enterprise customers can arrange a partner-operated deployment with us.

Managed SaaS

Hosted by
Bytesafe (Scaleway, France, default; AWS in the EU, optional on request)
Data location
EU
Operated by
Bytesafe

Ready to use. No infrastructure to provision or maintain.

BYO Cloud

Hosted by
Your cloud account
Data location
Your chosen region
Operated by
You

Full control over cloud account and region.

On-Premise

Hosted by
Your data center
Data location
Your data center
Operated by
You

Runs inside your network. No data leaves your environment.

Partner (MSP)

Hosted by
Arranged with a partner
Data location
Partner-defined
Operated by
Partner, arranged with Bitfront

Enterprise only. Scoped and arranged with us case by case, contact us to discuss.

Data and encryption

SaaS infrastructure runs on Scaleway in France by default, with AWS in the EU available on request. We store and process data within the EU.

  • All data in transit encrypted with TLS
  • All data at rest encrypted
  • Encryption keys managed with restricted, role-based access
  • Data backed up regularly, backups encrypted
  • Data stored and processed within the EU
  • GDPR Data Processing Agreement available
  • Subprocessor list published

Access and authentication

Access is identity-based. SSO and MFA are the perimeter.

  • SSO via your existing identity provider, all plans
  • MFA enforced for production and administrative access wherever the underlying system supports it
  • Role-based access, least-privilege principle
  • Access rights reviewed periodically and revoked within 48 hours of offboarding
  • Threat detection and edge controls in place for all production infrastructure
  • Network segmentation and environment separation between development and production

Application security

Security is part of every code review and release gate, not a final checklist.

  • Security review at design stage for all new features
  • Code review for all significant changes
  • Static analysis and dependency scanning in CI
  • We run Bytesafe Dependency Firewall on our own development pipeline

Vulnerability management

Findings are triaged by severity. Fixes are tracked against internal SLA targets.

  • Findings triaged by exploitability and exposure in the application context
  • Compensating controls applied where upstream fixes are not yet available
  • Audit logging across all production infrastructure

Responsible disclosure

If you believe you have found a security vulnerability in Bytesafe, please notify us. We will work with you to resolve the issue before public disclosure.

Email: security@bytesafe.dev

  • Make a good faith effort to avoid violating privacy, destroying data, or disrupting the service
  • Only interact with accounts you own or have explicit permission to test

Incident response

Report security issues to security@bytesafe.dev. Customer-impacting incidents are communicated via the public status page.

  • Service availability monitored by a third party
  • Personal data breaches notified to you within 72 hours, in line with GDPR Article 33
  • Custom SLA available for Enterprise customers

Who we are

Bytesafe is built and operated by Bitfront AB, incorporated in Sweden. We have been working on dependency security tooling since 2018.

Security is part of how we operate and develop our products: restricted access, secure development practices, vulnerability handling, and operational monitoring.

For organizations with strict compliance requirements, on-premise deployment, and a partner-operated deployment arranged with us, remove Bytesafe from the data path entirely.

Common questions

Where is data stored in the managed SaaS deployment?
On Scaleway infrastructure in France by default. AWS in the EU is available on request. We store and process it within the EU. Two subprocessors, Neon and Sinch Email, are US-established companies that process in the EU region we selected, covered by Standard Contractual Clauses. Full detail on our Subprocessors page.
Can we run Bytesafe in our own environment?
Yes. On-premise deployment is available. No Bytesafe sub-processors are involved in the data plane for on-premise deployments. Contact us to discuss requirements.
Who has access to our data in the SaaS deployment?
Bytesafe operations staff, under GDPR-compliant data processing terms. Production access requires SSO and MFA. A full Data Processing Agreement is available and can be countersigned on request.
What are your breach notification timelines?
We notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach. As processor our duty under Article 33(2) GDPR is to notify you, not the supervisory authority, which retains its own Article 33(1) obligations toward yours.

Talk to us about your requirements.

Whether you need SaaS, on-premise, or a partner deployment, we can walk through what fits your environment.

Book a Demo