Trust Center
Security
Effective Date: May 15, 2026 — Last Updated: August 15, 2026
Overview
Security is fundamental to the DEVUP AI architecture. We apply defense-in-depth practices to protect your API traffic, account data, and credentials.
Data Encryption
All data in transit is encrypted using TLS, securing communication between your applications and our API gateway. Account data and billing records are stored on Supabase, which applies encryption at rest at the platform level.
Trusted Infrastructure & Reliability
DEVUP AI runs on Hetzner infrastructure in Europe, with DNS managed through Cloudflare and database services provided by Supabase.
API Key Safety
DEVUP AI API keys are generated using cryptographically secure random number generators. Keys are stored as one-way cryptographic hashes; we cannot retrieve your plaintext key after it is generated.
HTTP Security Headers
Our edge enforces strict HTTP security headers across all endpoints: HTTP Strict Transport Security (HSTS) with a two-year max-age, includeSubDomains, and preload; X-Frame-Options set to DENY to prevent clickjacking; X-Content-Type-Options set to nosniff; a strict Referrer-Policy; and a Permissions-Policy disabling camera, microphone, and geolocation access.
Local Support & Incident Management
Security incidents, account access issues, and billing disputes are handled strictly by our Algeria-based support operations, ensuring rapid and culturally aligned resolution.
Data Protection Alignment
Security controls and data handling procedures are implemented in alignment with the requirements of Algerian Law 18-07 on the protection of personal data. Details of how personal data is collected, processed, and transferred are set out in our Privacy Policy.
Responsible Disclosure Policy
We take the security of our AI infrastructure seriously. If you believe you have discovered a vulnerability, please report it to our security team at support@devupai.com. We are committed to working with security researchers to verify and resolve any issues promptly.