Trust and policy

Security and data handling

Review LoadStrike self-hosted execution, data handling, and published SDK dependency scanning for customer and procurement teams.

Diagram showing self-hosted execution with runner-key validation and runtime access rules.
A clear product summary for security and procurement review.

What data does LoadStrike handle in the current product?

LoadStrike runs self-hosted in customer-controlled environments.

Licensed execution uses runner, environment, version, and entitlement metadata. It does not use application request or response payload bodies for access checks.

LoadStrike runs automated dependency scans every Monday at 06:00 UTC, and the same scan can be started manually. Each run resolves the latest stable published NuGet, npm, PyPI, Maven, and Go SDK packages and audits the runtime and transitive dependency graphs selected by temporary consumers. For Go, the scan also checksum-verifies and audits every supported execution artifact published for the exact selected module version. Any known vulnerability at any severity fails the relevant scan; a resolution, audit, or scanner error also fails.

Who this is for

Security, procurement, platform, and architecture teams reviewing LoadStrike.

Why enterprise reviews slow down here

Reviews slow down when product and data-handling details are scattered. This page gives the summary.

What this page confirms today

Use this page to separate self-hosted runtime execution from account, access, and support data.

Verified LoadStrike fit points

  • Self-hosted execution happens in customer-controlled infrastructure.
  • Runtime access checks use runner, environment, version, and entitlement metadata.
  • Licensing records support account management and plan access.
  • Signup and contact forms can require Cloudflare Turnstile verification.
  • Website privacy details are documented separately.
  • Security contact details are published at /.well-known/security.txt.
  • Published SDK dependency scans cover the latest stable NuGet, npm, PyPI, Maven, and Go packages.
  • The scan runs once a week on Monday at 06:00 UTC and can also be started manually.
  • Temporary consumers expose each package's runtime and transitive dependency graph for audit.
  • Every supported Go execution artifact for the exact selected module version is checksum-verified and audited.
  • Any known vulnerability at any severity makes the relevant scan fail.
  • A package resolution failure, incomplete dependency graph, audit error, scanner error, or timeout also makes the relevant scan fail.
  • A passing result is point-in-time only: automated scanning does not guarantee that software is vulnerability-free and does not provide a security certification.

Technical pages to review next

Related pages for product and buying review.

Pricing

Review the self-hosted commercial model.

Common questions

Common questions

Does LoadStrike store application payload bodies as part of runtime access checks?

No. Runtime access checks use runner, environment, version, and entitlement metadata.

Can public forms require human verification?

Yes. Signup and contact forms can require Cloudflare Turnstile verification.

Which published SDK packages are scanned?

The scan runs once a week on Monday at 06:00 UTC and can also be started manually. Each run independently resolves the latest stable published NuGet, npm, PyPI, Maven, and Go packages.

What does the published SDK dependency scan check?

Each temporary consumer selects the package's runtime and transitive dependency graph. The Go scan also checksum-verifies and audits every supported execution artifact for the exact selected module version. Any known vulnerability at any severity fails the relevant scan, and a resolution, audit, or scanner error fails too.

Does a passing automated scan guarantee that an SDK is vulnerability-free or certified?

No. A passing result is point-in-time only. Automated scanning does not guarantee that software is vulnerability-free and does not provide a security certification. Organizations should apply their own risk assessment and security controls.

How should security reports be sent?

Send security review requests and vulnerability disclosure questions to [email protected] or use the contact page security path. The site also publishes /.well-known/security.txt for automated discovery.

What data should security and procurement teams review first?

Start with this page, pricing, and website privacy, then contact LoadStrike if needed.

Where does website privacy fit into this picture?

Website analytics and contact-form handling are covered on the website privacy page.

Related

Related documentation

Start with the implementation details that match this page.

Cluster Overview

Cluster mode lets one LoadStrike run spread across multiple nodes. Use it when a single machine is not enough or when topology matters.

Quick Start

Build one basic request-step scenario around GET /orders/{id}, run it, and confirm the report before moving into correlation-specific features.

Next steps

Product

Review the self-hosted product model.

Pricing

Review plan-based access.

Contact

Route security review or procurement follow-up to the LoadStrike team.

Next step

Next step

Use this page for security review, then open pricing or contact LoadStrike.