Trust and policy

Security and data handling

Review LoadStrike self-hosted execution, data handling, and published SDK security assurance for customer and procurement teams.

Diagram showing self-hosted execution with runner-key validation and runtime access rules.
A clear product summary for security and procurement review.

What data does LoadStrike handle in the current product?

LoadStrike runs self-hosted in customer-controlled environments.

Licensed execution uses runner, environment, version, and entitlement metadata. It does not use application request or response payload bodies for access checks.

LoadStrike also runs automated security assurance once a week against the latest stable published SDK packages, with the same review available manually for an on-demand check. Each review resolves the packages from their official distribution channels and covers resolved consumer dependencies and the Go execution artifact used by the public Go package. PyPI dependency checks cover the release's declared CPython 3.9 through 3.14 targets on Linux x86-64, Windows AMD64, and macOS ARM64. Each declared Python minor starts at the lowest supported patch release allowed by package metadata, and compatible Linux wheel tags are considered. The matrix is bounded to eight declared extras and 180 target selections.

Who this is for

Security, procurement, platform, and architecture teams reviewing LoadStrike.

Why enterprise reviews slow down here

Reviews slow down when product and data-handling details are scattered. This page gives the summary.

What this page confirms today

Use this page to separate self-hosted runtime execution from account, access, and support data.

Verified LoadStrike fit points

  • Self-hosted execution happens in customer-controlled infrastructure.
  • Runtime access checks use runner, environment, version, and entitlement metadata.
  • Licensing records support account management and plan access.
  • Signup and contact forms can require Cloudflare Turnstile verification.
  • Website privacy details are documented separately.
  • Security contact details are published at /.well-known/security.txt.
  • Published SDK assurance covers the NuGet, npm, PyPI, Maven, and Go packages plus the Go execution artifact.
  • The review runs once a week against the latest stable published packages and can also be started manually when an on-demand check is needed.
  • Clean consumer checks assess resolved consumer dependencies rather than only the direct SDK package.
  • PyPI checks cover the base installation, every declared extra, and all extras together across the published CPython 3.9 through 3.14 target matrix. Each declared minor starts at the lowest supported patch release and compatible Linux wheel tags are considered. More than eight declared extras, more than 180 target selections, or an unbounded target condition fails the review.
  • Supported integrity and provenance checks are applied before vulnerability and package-content review.
  • Required advisory data must be fresh for the review; stale, unavailable, or incomplete evidence cannot produce a passing result.
  • Any known detected vulnerabilities or incomplete assurance evidence makes the security review fail with an explicit reason and details.
  • Automated assurance reduces risk, but it does not guarantee that software is vulnerability-free and does not provide a security certification.

Technical pages to review next

Related pages for product and buying review.

Pricing

Review the self-hosted commercial model.

Common questions

Common questions

Does LoadStrike store application payload bodies as part of runtime access checks?

No. Runtime access checks use runner, environment, version, and entitlement metadata.

Can public forms require human verification?

Yes. Signup and contact forms can require Cloudflare Turnstile verification.

Which published SDK releases receive automated security assurance?

The review runs once a week and can also be started manually. Each review independently resolves the latest stable NuGet, npm, PyPI, Maven, and Go packages from their official distribution channels, together with the matching Go execution artifact and resolved consumer dependencies. A required package that cannot be resolved or downloaded makes the review fail with details.

What does published SDK assurance verify?

Checks cover known detected vulnerabilities, fresh advisory data, and package content, plus supported integrity and provenance checks for each publishing ecosystem. PyPI dependency review covers the release's declared CPython 3.9 through 3.14 targets on Linux x86-64, Windows AMD64, and macOS ARM64 for the base installation, each declared extra, and all extras together. Each minor begins at the lowest supported patch release allowed by package metadata, and compatible Linux wheel tags are considered. More than eight declared extras, more than 180 target selections, or stale, unavailable, unbounded, or incomplete evidence is reported as a failed review with details.

Does a passing automated review guarantee that an SDK is vulnerability-free or certified?

No. Automated assurance reduces known risk, but it does not guarantee that software is vulnerability-free and does not provide a security certification. Organizations should apply their own risk assessment and security controls.

How should security reports be sent?

Send security review requests and vulnerability disclosure questions to [email protected] or use the contact page security path. The site also publishes /.well-known/security.txt for automated discovery.

What data should security and procurement teams review first?

Start with this page, pricing, and website privacy, then contact LoadStrike if needed.

Where does website privacy fit into this picture?

Website analytics and contact-form handling are covered on the website privacy page.

Related

Related documentation

Start with the implementation details that match this page.

Cluster Overview

Cluster mode lets one LoadStrike run spread across multiple nodes. Use it when a single machine is not enough or when topology matters.

Quick Start

Build one basic request-step scenario around GET /orders/{id}, run it, and confirm the report before moving into correlation-specific features.

Next steps

Product

Review the self-hosted product model.

Pricing

Review plan-based access.

Contact

Route security review or procurement follow-up to the LoadStrike team.

Next step

Next step

Use this page for security review, then open pricing or contact LoadStrike.