SECURITY AT BUGHERD

Trusted by teams across the world.

BugHerd is a cloud application platform used by teams of all sizes spanning over 170 countries around the world.

application security

Overview

BugHerd is built and operated by Splitrock Studio Pty Ltd, an Australian company. We hold our customers' data and take that responsibility seriously. This page summarises how we protect it and links to the documents most security reviews ask for. Our platform, performance and availability are monitored continuously.
arrow icon

Hosting

BugHerd runs on Salesforce Heroku, hosted on Amazon Web Services (AWS) in the us-east-1 region (Northern Virginia, USA). Screenshots and attachments are stored in AWS S3 in the same region. Heroku and AWS maintain SOC 2 and ISO 27001 attestations and are responsible for physical and infrastructure security; we are responsible for the application, its dependencies and our staff devices.
arrow icon
application security

Data Center Security

AWS infrastructure is housed in Amazon-controlled data centers, ensuring compliance with local regulations. The data centers are secured with a variety of physical controls to prevent unauthorized access. Click the link below to find out more information on AWS data centers and their security controls.
arrow icon
illustration - security more

More about BugHerd Security

icon

Encryption

All connections to BugHerd, including the browser extension, JavaScript embed and API, use TLS 1.2 or higher with HSTS enforced. TLS 1.0 and 1.1 are disabled. All production data at rest, including the database and stored screenshots and attachments, is encrypted with AES-256.
icon tick

Availability & Recovery

Real-time status and historical uptime are published at status.bugherd.com. Our database is protected by continuous point-in-time recovery (recovery point of approximately 5 minutes) with daily backups retained for 30 days. Our recovery time objective is 4 hours for a database restore and 8 hours for recovery from a regional outage. Contractual SLAs are available on custom plans.

Payment

Our payment partner maintains ongoing PCI compliance, abiding by stringent industry standards for storing, processing and transmitting credit card information online.

Privacy

You can view our full privacy
policy in the link below.
arrow icon

Real-time Status Transparency

We make it easy to stay informed on our system availability and performance at all times.
arrow icon

User Authentication

You control who can access your projects and what they can do. BugHerd supports single sign-on via SAML 2.0 with your identity provider (Okta, Microsoft Entra ID, Google Workspace and others), with SCIM provisioning to automate onboarding and offboarding. Where your identity provider enforces multi-factor authentication, that protection extends to BugHerd. Password-based login with role-based permissions is also available.

GDPR

We are bound by the Australian Privacy Principles contained in the Privacy Act and observe applicable principles of the European Union General Data Protection Regulations (‘GDPR’). For more information, please refer to our Privacy policy.

The service providers we use, and the data each one holds, are listed on our sub-processors page

Reporting a Vulnerability

If you believe you have found a security vulnerability in BugHerd, please email security@bugherd.com. We review all reports promptly and will keep you informed of our progress. We ask that you give us reasonable time to address an issue before disclosing it publicly, and that you do not access or modify data belonging to others while testing.

Data Retention and Deletion

Your data is retained for the life of your account. You can delete tasks, projects, users or your whole account at any time from within BugHerd. Deleted items are soft-deleted and permanently removed from production within 14 days, including screenshots and attachments; they expire from encrypted database backups within 30 days after that. Written confirmation of deletion is available on request. Production data is never copied to non-production environments.

Access Control

Access to production systems and customer data is granted on a least-privilege, need-to-know basis, protected by single sign-on and multi-factor authentication, logged, and reviewed at least every six months. Only engineering and customer support staff can access customer project content, and only for support or incident response. Staff devices are company-managed and encrypted, with remote wipe capability.
icon of technical information

Secure Development

All code changes require a second review and must pass automated tests before release. Application dependencies are continuously scanned for vulnerabilities using Dependabot and Snyk. Critical vulnerabilities are addressed immediately; anything known to be actively exploited is treated as critical regardless of its rating.
icon

Artificial Intelligence

BugHerd's AI features are optional and off by default. When enabled, only task titles and descriptions are sent to our AI provider; screenshots, attachments and user identities never are. Inputs are not used to train models and are deleted by the provider after 30 days. AI suggestions must be accepted by a user before they change anything. Our AI Features Security and Privacy Overview is available on request.

Security Documentation

The following are available to customers and prospects completing a security review:

Privacy Policy
Sub-processor register
System status and uptime history

Available on request:

- Information Security Policies (PDF)
- AI Features Security & Privacy (PDF)

To request documents or ask a security question, contact security@bugherd.com.

For Custom Plans we are happy to complete customer security questionnaires.

Constant updates and innovation

We’re consistently updating BugHerd to ensure optimal performance and new features. Updates are delivered frequently without interrupting your service.
arrow icon

Got any questions?

For answers to your own specific security questions, get in touch with a member from our support team.
Contact us