Skip to main content

Security at Structor

We take security seriously and are honest about what’s shipped today vs. what’s on the roadmap. If you find an issue, please email security@gostructor.com.

Hosting

Structor runs on managed cloud infrastructure with a 99.9% uptime target. Production workloads are deployed in EU and US regions. [planned Q3] region pinning per workspace.

Encryption

  • In transit: TLS 1.2+ enforced on every endpoint.
  • At rest: Databases and backups are encrypted at rest with AES-256.
  • WordPress credentials: Encrypted with per-org keys and never exposed to the browser.

Authentication

  • Email + password with bcrypt hashing.
  • Optional 2FA via authenticator apps. [planned Q3] WebAuthn / passkeys.
  • Google SSO on Business plans, SAML SSO on Enterprise.

Data deletion

You can delete your workspace from the app at any time. We purge primary records within 30 days and from backups within 90 days. Email privacy@gostructor.com for a written confirmation.

Sub-processors

ProviderPurposeLocation
Cloud hostingApplication & database hostingEU / US
OpenAIAI model inference for content analysisUS
StripeBilling & payment processingUS / EU
Resend / SMTPTransactional email deliveryUS / EU
Matomo (self-hosted)Privacy-friendly analyticsEU

Vulnerability disclosure

We accept reports at security@gostructor.com. We aim to acknowledge reports within 2 business days and to fix critical issues within 30 days. We do not currently run a paid bug bounty [planned Q4].

Status

Live system status is available at https://status.gostructor.com.