Published 2026-04-10 | Updated 2026-07-24 | LoadStrike Editorial Team
Review LoadStrike self-hosted execution, data handling, and published SDK security assurance for customer and procurement teams.
A clear product summary for security and procurement review.
What data does LoadStrike handle in the current product?
LoadStrike runs self-hosted in customer-controlled environments.
Licensed execution uses runner, environment, version, and entitlement metadata. It does not use application request or response payload bodies for access checks.
LoadStrike also runs automated security assurance once a week against the latest stable published SDK packages, with the same review available manually for an on-demand check. Each review resolves the packages from their official distribution channels and covers resolved consumer dependencies and the Go execution artifact used by the public Go package. PyPI dependency checks cover the release's declared CPython 3.9 through 3.14 targets on Linux x86-64, Windows AMD64, and macOS ARM64. Each declared Python minor starts at the lowest supported patch release allowed by package metadata, and compatible Linux wheel tags are considered. The matrix is bounded to eight declared extras and 180 target selections.
Who this is for
Security, procurement, platform, and architecture teams reviewing LoadStrike.
Why enterprise reviews slow down here
Reviews slow down when product and data-handling details are scattered. This page gives the summary.
What this page confirms today
Use this page to separate self-hosted runtime execution from account, access, and support data.
Verified LoadStrike fit points
Self-hosted execution happens in customer-controlled infrastructure.
Runtime access checks use runner, environment, version, and entitlement metadata.
Licensing records support account management and plan access.
Signup and contact forms can require Cloudflare Turnstile verification.
Website privacy details are documented separately.
Security contact details are published at /.well-known/security.txt.
Published SDK assurance covers the NuGet, npm, PyPI, Maven, and Go packages plus the Go execution artifact.
The review runs once a week against the latest stable published packages and can also be started manually when an on-demand check is needed.
Clean consumer checks assess resolved consumer dependencies rather than only the direct SDK package.
PyPI checks cover the base installation, every declared extra, and all extras together across the published CPython 3.9 through 3.14 target matrix. Each declared minor starts at the lowest supported patch release and compatible Linux wheel tags are considered. More than eight declared extras, more than 180 target selections, or an unbounded target condition fails the review.
Supported integrity and provenance checks are applied before vulnerability and package-content review.
Required advisory data must be fresh for the review; stale, unavailable, or incomplete evidence cannot produce a passing result.
Any known detected vulnerabilities or incomplete assurance evidence makes the security review fail with an explicit reason and details.
Automated assurance reduces risk, but it does not guarantee that software is vulnerability-free and does not provide a security certification.
Use the security and compliance contact path for follow-up review.
Common questions
Common questions
Does LoadStrike store application payload bodies as part of runtime access checks?
No. Runtime access checks use runner, environment, version, and entitlement metadata.
Can public forms require human verification?
Yes. Signup and contact forms can require Cloudflare Turnstile verification.
Which published SDK releases receive automated security assurance?
The review runs once a week and can also be started manually. Each review independently resolves the latest stable NuGet, npm, PyPI, Maven, and Go packages from their official distribution channels, together with the matching Go execution artifact and resolved consumer dependencies. A required package that cannot be resolved or downloaded makes the review fail with details.
What does published SDK assurance verify?
Checks cover known detected vulnerabilities, fresh advisory data, and package content, plus supported integrity and provenance checks for each publishing ecosystem. PyPI dependency review covers the release's declared CPython 3.9 through 3.14 targets on Linux x86-64, Windows AMD64, and macOS ARM64 for the base installation, each declared extra, and all extras together. Each minor begins at the lowest supported patch release allowed by package metadata, and compatible Linux wheel tags are considered. More than eight declared extras, more than 180 target selections, or stale, unavailable, unbounded, or incomplete evidence is reported as a failed review with details.
Does a passing automated review guarantee that an SDK is vulnerability-free or certified?
No. Automated assurance reduces known risk, but it does not guarantee that software is vulnerability-free and does not provide a security certification. Organizations should apply their own risk assessment and security controls.
How should security reports be sent?
Send security review requests and vulnerability disclosure questions to [email protected] or use the contact page security path. The site also publishes /.well-known/security.txt for automated discovery.
What data should security and procurement teams review first?
Start with this page, pricing, and website privacy, then contact LoadStrike if needed.
Where does website privacy fit into this picture?
Website analytics and contact-form handling are covered on the website privacy page.
Related
Related documentation
Start with the implementation details that match this page.