Polestead is built to run where you decide — up to and including fully air-gapped. When the platform lives inside your walls, there is no third-party attack surface to inherit and no foreign jurisdiction to answer to.
On-premises, air-gapped, single-tenant EU cloud, or managed single-tenant SaaS. You choose the boundary your data lives inside.
Data encrypted in transit (TLS) and at rest. Secrets are managed, rotated, and never written to logs.
Row-level security in the database and single-tenant instances for the managed and EU-cloud models — no co-mingled customer data.
Role-based access control, SSO/SAML for managed deployments, and scoped API entitlements. Access is granted narrowly and reviewed.
Inference runs on your keys or not at all. Your data never trains our models — structurally, because it never reaches our infrastructure.
Code review, dependency and secret scanning in CI, and periodic third-party penetration testing of the managed service.
Polestead is new. Rather than borrow badges, we publish where each framework actually stands. Because you can self-host, your own auditors can inspect the deployment directly.
Status labels reflect Polestead's position as of the last-updated date and will change as certifications complete. We will never display a badge we haven't earned.
We run a responsible-disclosure programme. Report suspected vulnerabilities to security@polestead.com — we acknowledge promptly, keep you updated, and will not pursue good-faith research that follows the policy. Please don't access data that isn't yours or degrade the service while testing.
We're new. Controls are designed to SOC 2 and ISO 27001 criteria and certification is on the roadmap — we publish honest status, not borrowed badges. Self-hosting lets your own auditors inspect the deployment directly.
Your register, assessments, and incident records never leave your environment — no third-party attack surface to inherit, no cross-border compulsion question.
Only if you enable AI with your own keys, in which case the call goes to your provider under your terms. Zero-AI runs with no external inference. We never train on your data.
Email security@polestead.com. We run a responsible-disclosure programme, acknowledge promptly, and protect good-faith researchers who follow the policy.