Security

Last updated: October 26, 2025

Vendor summary

CategoryVendorData handled
Edge & networkingCloudflareRequest metadata for routing, WAF, and DDoS protection
Application runtimeFly.ioApplication services, secrets, deployment logs
DatabaseNeonPostgres records with encryption at rest and PITR
AI inferenceOpenAIPrompts and responses with no training usage
AI observabilityLangfusePrompt metadata and metrics
Crawl automationFirecrawlPublic web pages fetched for evaluation
Background jobsTrigger.devScoped workflow payloads for background jobs
Web searchExaGenerated search queries only
MonitoringSentrySanitized error traces (90-day retention)
Product analyticsPosthogAggregate usage events without source code
BillingStripePayment instruments, invoices, and tax details

Contact & disclosure

Please send questions and responsible disclosure reports to security@mistle.dev.