Trust

Compliance

A transparent summary of what's actually in place today, and what's still on the roadmap, for procurement and security review workflows.

In place today

  • Local-first architecture: bug report content (screenshots, DOM snapshots, console/network logs) stays on-device by default and is not uploaded to BugBundler's servers, which removes most cross-border transfer questions entirely.
  • Account and billing data is processed exclusively in EU regions — Cloud Functions in Finland (europe-north1), Firestore in Stockholm, Sweden (europe-north2).
  • A Data Processing Agreement is available for organizations that need one.
  • Subprocessors are disclosed on the Privacy page, including the two (Stripe, Resend) that operate outside the EU under Standard Contractual Clauses.

Not yet in place

We haven't completed a SOC 2 or ISO 27001 audit yet. If your procurement process requires one, tell us on a call — we track this as a roadmap item and can share our current security practices in detail in the meantime.

Enterprise & procurement review

  • Security questionnaires: available on request.
  • DPA review and execution: available on request.
  • Enterprise review support available via demo call.