Trust & security

Mechanisms, not adjectives. Every line here describes something the platform does today; where we have nothing to show, this page says nothing.

Where your data sits

Servers run in OVH datacentres: Beauharnois, Canada for the NA region and Gravelines, France for EU. You pick the region when you create a server, and a server stays in the region you picked.

Your backups are never locked behind a ticket

Every server's backups are written on the box it runs on. You can download any of them yourself from the panel — no ticket, no waiting — and a full world download works the same way.

Nodes authenticate each other

The control plane and every remote node speak over mutual TLS with per-node certificates, so a node cannot be impersonated by anything that merely reaches the network.

Card data never reaches our servers

Payments go through Paddle as merchant of record. Card data is entered on their side; we receive a signed webhook and a balance, never a card number.

The panel never hands your key to the browser

The dashboard talks to the API only from the server side, carrying a service key the browser never sees, plus your account identity from a signed session cookie.

File access is per-server and jailed

SFTP credentials are issued per server and confined to that server's directory, so one set of credentials cannot read another server's files.

Getting your data out is self-service

Worlds and backups download from the panel at any time. Unused credit is refundable — see the refund policy.

Live checks and the incident log: /status.