Skip to main content

Security

How Tensel isolates your applications, protects your secrets, and prepares for incidents.

Isolation

Each environment runs in its own container, never a shared process between customers. Builds run untrusted code: each build runs in a disposable virtual machine, destroyed after use, with no access to platform networks.

Secrets

Your secrets are encrypted at rest before they reach the database, injected only at runtime, and never written to logs. Secret writes are audited.

Auditability

Sign-ins, role changes, secret writes and deployments are recorded in a browsable audit log, retained for one year.

Continuity

The platform database is snapshotted every 6 hours and restoration is proven by real drill (last drill: 7 min 49 s to verified data). The platform is monitored with alerts on queues, containers and the database.

Where your data lives

Every platform capability, the kind of service behind it, and where it runs. Everything is in Paris, except the optional integrations we disclose.

CapabilityServiceLocationStatus
Compute (your applications)Serverless containers from a European hostParis, one container per environmentIn production
Static site deliveryEuropean CDN (BunnyWay, Slovenia)European points of presence (EU, Switzerland, UK, Norway); origin in ParisIn production
BuildsDisposable virtual machinesParis, destroyed after every buildIn production
Container imagesPrivate container registryParis, private registryIn production
Platform databaseManaged PostgreSQL (European host)ParisIn production; restoration proven by drill (2026-08)
Platform secretsSecrets manager + application-level encryptionParisIn production
MonitoringThe host's native metrics and logsParisIn production
Sign-in emailsEuropean transactional email serviceParis; verified domainIn production
IdentitySelf-operated (better-auth) in our own databaseParis; GitHub/Google optional and disclosedIn production
Source code integrationGitHub (App)US service, optional, scope limited to the repoDisclosed
PaymentsMollie (Netherlands)European contracting entity; processing and transfer evidence pendingAdapter ready; collection disabled pending production approval

Report a vulnerability

Write to security@tensel.eu. We acknowledge reports within 2 business days, we do not take legal action against good-faith research, and we credit you if you wish.