Security and trust
Burgndy.ai handles your app ideas, source code and the keys you connect. Here is what we do to protect them, and what we have not done yet. We would rather be plain than impressive.
Your service credentials are encrypted
API keys you connect (for example a Razorpay key or a Twilio token) are encrypted with Google Cloud KMS before they are stored. They are decrypted only on our servers at the moment they are needed, and are never sent to your browser or shipped inside a generated app.
Apple credentials are not kept
Apple Developer credentials used for iOS signing and uploads are sent with each request and are not stored on our servers.
Payments are verified on the server
When a generated app takes a payment through Razorpay, the payment signature is checked on our server against the merchant's own key, and orders are tied to the specific app so they cannot be replayed against another.
Builds run in isolated sandboxes
Each Studio session runs in its own container with its own temporary working folder. The sandbox services are not open to the internet: only a small preview gateway is public, and it forwards preview traffic only. Every deployed web app runs as its own separate service.
Deploys are scanned for leaked keys
Before a web app is published, its files are scanned for API-key patterns. A deploy that contains a leaked secret is blocked.
Your data is yours to read, and mostly ours to write
Sign-in uses Firebase Authentication. Access rules limit account data to its owner, and most records can only be written by our own server functions, not directly from the browser.
What we have not done
- No security certification yet. We do not hold SOC 2 or ISO 27001, and we have not had an independent security audit. If you need those for your organization, Burgndy.ai is not ready for you yet.
- We are pre-launch. The product is new, has few users, and will have bugs. We fix what we find and list changes on the changelog.
- Testing is on an emulator and Simulator. That does not replace testing on physical phones for camera, biometrics and real-world performance.
Your part
- Publish under your own Apple Developer and Google Play accounts. The store apps belong to you.
- Keep your GitHub repository and any keys you connect under your control. You can disconnect a service at any time.
- Review generated code before you ship it to real users, as you would any code you did not write.
Found a vulnerability? Please tell us privately through the contact page before sharing it publicly. The founder reads every report.