Security Statement
Last updated: December 1, 2026
This statement describes how Dunzio Inc ("Dunzio") protects the studio and the data in it.
1. Safeguards in place
- In transit. Every request to the studio, and to the backend of an app you build, is encrypted with TLS.
- At rest. Data is stored with Amazon Web Services in the United States (the us-east-1 region), with the platform's managed encryption.
- Sign-in. You sign in with an email address and password, or with Google or GitHub. Passwords are stored only as salted hashes. Sessions expire, and you can sign out at any time.
- Secrets. A developer key is shown once, when it is created, and can be replaced from the project's Admin Panel.
- Payments. Card details go directly to Stripe. Dunzio never receives or stores card numbers.
- Separation. Each app's data is logically separated from every other app's data.
2. The standard we hold to
Dunzio uses commercially reasonable safeguards to protect your data. No system is perfectly secure, and Dunzio does not guarantee that the Service or your data will never be accessed, lost or changed without authorization.
You are responsible for keeping your password and developer keys secret, and for the security of the apps you deploy.
3. Third-party technology and providers
The Service depends on technology and services that other companies operate, including cloud hosting, payment processing and AI models. Dunzio is not responsible for failures of that underlying technology or of those service providers.
4. Reporting a security problem
If you believe you have found a vulnerability, or that your account has been accessed without your permission, write to james@dunzio.com. Security reports are read first.