Skip to main content
Percher is still being built and account creation is paused — get notified when it opens.

Security and isolation

How apps, accounts and data are kept apart and protected

Ask your agent
Explain how Percher keeps my app, account and data separate from other customers, and what I still need to secure in my own app.Read the guide at percher.app/docs/security-and-isolation

How it works, with exact details

How are apps kept apart?

Each app runs in its own containers on its own private network. An app can reach its own database and, with limits, the internet, but it has no direct route to other apps or to the systems that run Percher. App containers run with minimal privileges. If your app uses Percher's database, it gets its own instance with its own storage.

How is my account protected?

You sign in to Percher with an email address and a password. Your Percher account password is stored only as a salted hash, never in clear text. New accounts confirm their email address, sign-up and password reset include a bot check, and sign-in attempts are rate limited. Resetting your password signs out all your existing sessions.

What is encrypted?

Traffic to Percher and to your apps uses HTTPS. Environment variables, KV store values and webhook signing secrets are encrypted at rest with AES-256. Percher API tokens and deploy hook links are stored only as hashes, so they cannot be read back. Nightly backups are encrypted with AES-256 and kept off-site for up to 30 days.

Who at Percher can see my app and data?

Percher staff can technically reach data hosted on the platform, because we run the servers and hold the keys that decrypt stored secrets. That access is limited by our own rules, not blocked by encryption. We do not open your code, logs, database or secrets to answer a support request; if we need to see something, we ask you to send it. If an app puts other customers or the platform at risk, we may stop it. Stopping an app leaves its code and data as they are.

Where is my data stored?

Your apps, their data and their backups are hosted in the EEA, in Germany and Finland. Some providers we use, for example for email and payments, process limited data outside the EEA. The privacy policy and the subprocessor list name each one.

How do I report a vulnerability?

Email security@percher.app. The security policy explains what to include, what is in scope and what to expect.