Security & Trust
How Productapp hosts, protects, and handles your organization's data.
Hosting & infrastructure
Productapp runs on Vercel, with organization data in PostgreSQL on Neon and background workflows on Inngest. Application code and infrastructure are managed in the same repository — no undocumented shadow environments.
Data handling
Productapp is built in the EU with controls and practices aligned with GDPR data protection expectations. Transactional and notification email is sent through Mailgun's EU region.
Authentication & access
Sign-in is handled by Better Auth with hashed credentials, optional two-factor authentication, and organization-scoped roles. Enterprise plans add single sign-on.
Backups & recovery
Database backups run continuously via Neon's point-in-time recovery, with 7 days of retention.
Subprocessors
Services Productapp relies on to operate, and what each one is used for.
| Vercel | Application hosting and edge functions |
| Neon | PostgreSQL database |
| Upstash | Redis for rate limiting and caching |
| Meilisearch | Full-text search across the software marketplace |
| Mailgun | Transactional and notification email (EU region) |
| LemonSqueezy | Billing and payment processing |
| ImageKit | Image storage and delivery |
| Cloudflare | DNS and web application firewall |
| Fernand | In-app customer support messaging |
| Inngest | Background jobs and scheduled workflows |
Productapp does not hold a SOC 2 or ISO 27001 certification today. This page will be updated if that changes.
Support
Support email: Email available in browser