Skip to content

Security

Built for operators who keep credentials close

DBHelm is a desktop control plane. Secrets stay on your machine by default. We do not claim SOC 2, ISO 27001, or HIPAA certification today — this page is an honest posture summary for enterprise evaluation.

Desktop defaults

  • Credentials and kubeconfigs encrypted at rest (AES-256-GCM) in local SQLite
  • Offline-first after install — no phone-home of your database contents
  • Read-only Console by default; destructive ops require explicit confirm
  • Local RBAC (super-admin / admin / read-only) with org isolation
  • Optional opt-in error reporting only — off unless you enable it

Accounts & billing

Download and subscription management use a Cloudflare-hosted accounts API: email one-time codes, download logging, license issuance, and device seat activation. Paid checkout and invoices are handled by Lemon Squeezy. See the Privacy Policy for data categories.

Threat model (summary)

  • Protect Local credential store, kubeconfigs, and org-scoped access inside the desktop app
  • Assume hostile Untrusted SQL/MQL pasted into Console — hence read-only default + destructive-op confirm
  • Trust boundary Your machine and networks you configure; we do not sit in the data path as a SaaS proxy
  • Out of scope today SOC 2 / ISO attestation, formal pen-test reports, and public bug bounty
  • Air-gap Installer may be transferred offline; paid features use offline Ed25519 license keys

Compliance tooling vs certifications

Platform includes a compliance policy engine for fleet checks you define. UI mocks may show framework labels (for example SOC2) as roadmap tags — they are not evidence that DBHelm or your environment is certified.

Vulnerability disclosure

Report security issues to security@dbhelm.com. Please include steps to reproduce and impact. We do not run a public bug bounty today.

Also see /.well-known/security.txt.

Enterprise / volume

For multi-seat, procurement, or security questionnaires: /contact or hello@dbhelm.com.