burgndy.ai

Security and trust

Burgndy.ai handles your app ideas, source code and the keys you connect. Here is what we do to protect them, and what we have not done yet. We would rather be plain than impressive.

Your service credentials are encrypted

API keys you connect (for example a Razorpay key or a Twilio token) are encrypted with Google Cloud KMS before they are stored. They are decrypted only on our servers at the moment they are needed, and are never sent to your browser or shipped inside a generated app.

Apple credentials are not kept

Apple Developer credentials used for iOS signing and uploads are sent with each request and are not stored on our servers.

Payments are verified on the server

When a generated app takes a payment through Razorpay, the payment signature is checked on our server against the merchant's own key, and orders are tied to the specific app so they cannot be replayed against another.

Builds run in isolated sandboxes

Each Studio session runs in its own container with its own temporary working folder. The sandbox services are not open to the internet: only a small preview gateway is public, and it forwards preview traffic only. Every deployed web app runs as its own separate service.

Deploys are scanned for leaked keys

Before a web app is published, its files are scanned for API-key patterns. A deploy that contains a leaked secret is blocked.

Your data is yours to read, and mostly ours to write

Sign-in uses Firebase Authentication. Access rules limit account data to its owner, and most records can only be written by our own server functions, not directly from the browser.

What we have not done

Your part

Found a vulnerability? Please tell us privately through the contact page before sharing it publicly. The founder reads every report.