Trust Center | Ghostable                           Trust Center

 Your project secrets never enter Ghostable infrastructure.
============================================================

 Ghostable is local-first, repository-native software. Encrypted project state travels through the Git provider you choose; encryption and decryption happen on authorized devices and runners.

   No hosted vault
---------------

Ghostable does not store your project secrets or repository state.

    Local decryption
----------------

Plaintext exists only where you intentionally authorize it to run.

       Git-native review
-----------------

Encrypted values, access policy, and signed records move through normal code review.

  Security boundary

 A smaller trust boundary by design.
-------------------------------------

 Ghostable removes a Ghostable-operated secrets control plane from the workflow. The systems that can access plaintext are the systems you choose.

 ### Your repository

 Git stores encrypted values and signed metadata. Repository readers can inspect project structure and history, but ciphertext alone cannot decrypt a value.

  ### Authorized devices

 Private device identities stay outside Git. Authorized local devices decrypt only the environments granted to them.

  ### Automation

 CI runners use scoped credentials. Decrypted values reach a process or deployment provider only when an authorized workflow intentionally sends them there.

  ### Ghostable services

 Our hosted services are outside the project encryption path. They do not receive plaintext secrets, encrypted project state, private identities, or automation credentials.

  Supporting services

 What Ghostable does host.
---------------------------

 Ghostable operates the public website, documentation, release downloads and update metadata, Desktop licensing, and support workflows. These services help deliver and support the software, but none sits between your project and its secrets.

### Website and documentation

Product information, learning resources, security guidance, and support.

### Releases and updates

Signed software, download delivery, checksums, and update metadata.

### Desktop licensing

A Desktop license unlocks the app. It is not attached to any project and grants no project access, encryption keys, or decryption rights.

### Customer support

Support inquiries and security reports. Never include project secrets in a request.

Release integrity

 Verify what you install.
--------------------------

 Ghostable publishes verifiable release evidence for security review workflows, including checksums, software bill of materials artifacts, and signed build provenance where supported. Desktop releases include code-signing and notarization verification guidance.

 [ Review public security resources   ](https://ghostable.dev/docs/3.x/reference/security#resources)

  Operational security

 The controls that still matter.
---------------------------------

 A local-first architecture reduces Ghostable’s access to sensitive data. It does not remove our responsibility to ship trustworthy software and operate the supporting services safely.

- Least-privilege access to build, release, licensing, and support systems.
- Source control, code review, automated tests, and change-management checks.
- Dependency monitoring and vulnerability remediation.
- Protected code-signing, notarization, and release credentials.
- Incident response and responsible disclosure procedures.
- Focused vendor review for the supporting services we actually use.

  Independent assurance

 Current status.
-----------------

 Ghostable has not completed a SOC 2 examination, and no audit window is currently announced. We maintain security practices appropriate to the services we operate and will update this page if an independent examination is scheduled or completed.

Security resources

 Inspect the model. Report what you find.
------------------------------------------

 Our public security reference documents the cryptographic model, trust boundaries, residual risks, operational responsibilities, and disclosure process.

 [ Read the security reference   ](https://ghostable.dev/docs/3.x/reference/security) [ Report a vulnerability   ](https://ghostable.dev/security)
