Security & Trust

How Productapp hosts, protects, and handles your organization's data.

Hosting & infrastructure

Productapp runs on Vercel, with organization data in PostgreSQL on Neon and background workflows on Inngest. Application code and infrastructure are managed in the same repository — no undocumented shadow environments.

Data handling

Productapp is built in the EU with controls and practices aligned with GDPR data protection expectations. Transactional and notification email is sent through Mailgun's EU region.

Authentication & access

Sign-in is handled by Better Auth with hashed credentials, optional two-factor authentication, and organization-scoped roles. Enterprise plans add single sign-on.

Backups & recovery

Database backups run continuously via Neon's point-in-time recovery, with 7 days of retention.

Subprocessors

Services Productapp relies on to operate, and what each one is used for.

VercelApplication hosting and edge functions
NeonPostgreSQL database
UpstashRedis for rate limiting and caching
MeilisearchFull-text search across the software marketplace
MailgunTransactional and notification email (EU region)
LemonSqueezyBilling and payment processing
ImageKitImage storage and delivery
CloudflareDNS and web application firewall
FernandIn-app customer support messaging
InngestBackground jobs and scheduled workflows

Productapp does not hold a SOC 2 or ISO 27001 certification today. This page will be updated if that changes.

Support

Support email: Email available in browser