Security

We touch your production server. Here is how we keep it safe.

Wemazu holds the keys to servers you own, so trust is the whole product. This page is the plain version of how credentials are stored, who can reach what, and what happens to your data.

Where your credentials live

SSH keys are generated by Wemazu so your private key never leaves us. FTP credentials and Git tokens are encrypted at rest with AES-256 and isolated per organization. None of them are ever printed to a deploy log or shown in full once saved.

Encryption, end to end

Everything in transit runs over TLS 1.3 or an SSH channel. Everything at rest, secrets and environment variables included, is encrypted before it hits disk. App variables and platform secrets are stored separately, so one is never exposed by the other.

Who can reach production

Production is locked to named people. Lower environments stay open to your developers. A role matrix controls every action, SSO can be enforced for the whole organization, and every deploy and rollback carries who triggered it and why.

Your data and GDPR

Wemazu is built and hosted in Europe. We store the orchestration metadata, not your application data, which stays on your servers. You can export or delete your account data on demand, and a data processing agreement is available on request. Billing is handled by Simezu, who own the payment data.

Found something? Tell us first.
We run a responsible disclosure programme. Email the details and we will confirm within one business day, fix it, and credit you if you would like.
security@wemazu.com