Security
Built for operators who keep credentials close
DBHelm is a desktop control plane. Secrets stay on your machine by default. We do not claim SOC 2, ISO 27001, or HIPAA certification today — this page is an honest posture summary for enterprise evaluation.
Desktop defaults
- Credentials and kubeconfigs encrypted at rest (AES-256-GCM) in local SQLite
- Offline-first after install — no phone-home of your database contents
- Read-only Console by default; destructive ops require explicit confirm
- Local RBAC (super-admin / admin / read-only) with org isolation
- Optional opt-in error reporting only — off unless you enable it
Accounts & billing
Download and subscription management use a Cloudflare-hosted accounts API: email one-time codes, download logging, license issuance, and device seat activation. Paid checkout and invoices are handled by Lemon Squeezy. See the Privacy Policy for data categories.
Threat model (summary)
- Protect Local credential store, kubeconfigs, and org-scoped access inside the desktop app
- Assume hostile Untrusted SQL/MQL pasted into Console — hence read-only default + destructive-op confirm
- Trust boundary Your machine and networks you configure; we do not sit in the data path as a SaaS proxy
- Out of scope today SOC 2 / ISO attestation, formal pen-test reports, and public bug bounty
- Air-gap Installer may be transferred offline; paid features use offline Ed25519 license keys
Compliance tooling vs certifications
Platform includes a compliance policy engine for fleet checks you define. UI mocks may show framework labels (for example SOC2) as roadmap tags — they are not evidence that DBHelm or your environment is certified.
Vulnerability disclosure
Report security issues to security@dbhelm.com. Please include steps to reproduce and impact. We do not run a public bug bounty today.
Also see /.well-known/security.txt.
Enterprise / volume
For multi-seat, procurement, or security questionnaires: /contact or hello@dbhelm.com.