Trust
Compliance
A transparent summary of what's actually in place today, and what's still on the roadmap, for procurement and security review workflows.
In place today
- Local-first architecture: bug report content (screenshots, DOM snapshots, console/network logs) stays on-device by default and is not uploaded to BugBundler's servers, which removes most cross-border transfer questions entirely.
- Account and billing data is processed exclusively in EU regions — Cloud Functions in Finland (europe-north1), Firestore in Stockholm, Sweden (europe-north2).
- A Data Processing Agreement is available for organizations that need one.
- Subprocessors are disclosed on the Privacy page, including the two (Stripe, Resend) that operate outside the EU under Standard Contractual Clauses.
Not yet in place
We haven't completed a SOC 2 or ISO 27001 audit yet. If your procurement process requires one, tell us on a call — we track this as a roadmap item and can share our current security practices in detail in the meantime.
Enterprise & procurement review
- Security questionnaires: available on request.
- DPA review and execution: available on request.
- Enterprise review support available via demo call.