Trust

Security overview

BugBundler minimizes attack surface by keeping bug-capture data local and avoiding mandatory cloud upload of report artifacts.

Security principles

  • Local data processing for report generation.
  • No always-on server dependency for bug report payloads.
  • User-controlled distribution of exported report files.

Infrastructure

  • Account, workspace, and billing data is hosted on Google Cloud: Cloud Functions in Finland (europe-north1) and Firestore in Stockholm, Sweden (europe-north2) — both EU regions.
  • Data in transit is encrypted via TLS; data at rest is encrypted using Google Cloud's default encryption for Firestore and Cloud Functions.
  • Payment card data is handled directly by Stripe under its own PCI-DSS certified infrastructure — BugBundler never stores full card numbers.

What we don't have

Because report content isn't uploaded by default, there is no central store of screenshots, DOM snapshots, or console/network logs on BugBundler's servers to secure, breach, or subpoena. We also don't run analytics or session-replay SDKs inside the extension.

Formal certifications

BugBundler has not yet completed a SOC 2 or ISO 27001 audit. See Compliance for current status and roadmap — we'd rather state that plainly than imply a certification we don't hold.