Package-Master

Prove what you publish

Security posture and data residency

Package-Master runs inside your environment. This page states what we hold, what we never receive, and who else is involved.

What we never receive

Package-Master does not phone home. It sends no telemetry, no usage data, and no fleet inventory to us. Upstream sync requires outbound access.

Where the product runs

Self-hosted against PostgreSQL in your network. Your deployment initiates sync with approved upstream sources and serves packages internally. Physical transfer into fully disconnected networks is in development.

Jurisdiction

Package-Master runs inside your network. We never receive your package data, so there is no vendor-side copy of it for any court, in any country, to compel. Nothing needs to reach us to keep the product running: licensing works offline and there is no phone-home. The vendor is also Canadian-owned, a product of 1001379963 Ontario Inc., which can matter for procurement under Canada's Buy Canadian policy and CPCSC rules. A Canadian-controlled deployment can reduce some jurisdictional risks. It does not remove every legal or supply-chain risk.

Subprocessors

The self-hosted product has none: it runs in your environment and sends nothing to us or anyone else. Our business operations use GitLab (site hosting and source), Cloudflare (CDN and storage, served from Canada), Stripe (billing and checkout), Microsoft 365 (email), HubSpot (lead forms), and Anthropic (internal AI tooling). None of these ever hold your fleet's package data, because we never receive it in the first place.

Data residency

Product data (your package inventory, snapshots and policies) stays in your environment.

Incident policy

Report security issues to [email protected]. If an incident affects your data, we commit to notifying you by email within 72 hours of becoming aware of it.

Authentication today

Role-based bearer-token authentication. Package-Master does not ship SAML or SCIM.

See supported releases and limits