Security
How we keep Epistola secure
Whether you host Epistola yourself or we host it for you, this is how we keep it and your documents secure.
Open and checked code
Epistola is open source, so anyone can see how it works. Every change is reviewed and goes through automated checks, tests and a scan of the components it uses before it is released.
This website and your account
Our website, sign-in service and demo environments run on our own servers at Hetzner in Germany. All connections use HTTPS.
- Signing in happens at our sign-in service, auth.epistola.app, which also supports passkeys. The website itself never sees or stores your password.
- Sign-in cookies are encrypted, cannot be read by scripts on the page, and are only sent over secure connections.
- When you sign out, we also revoke your sign-in at the sign-in service, so a copied cookie can no longer keep someone signed in.
- The website only runs scripts it has explicitly allowed, through a strict Content Security Policy.
Hosting it yourself
When you run Epistola yourself, your organisation stays in control of the servers, the network and who has access. For your IT team, we recommend running the part that creates documents separately from other systems, encrypting every connection (TLS), and monitoring generated documents for unauthorised changes.
Hosted by us
When we host Epistola for you, your environment is kept separate from other customers, stored data is encrypted, and everything is monitored around the clock. Hosting within the EU is available on request.
Reporting a security problem
Found a vulnerability? Report it privately to security@epistola.app. We confirm receipt within two business days and work with you on a fix. Our security.txt lists the same contact.
Please give us reasonable time to fix a problem before you make it public, and do not access other people’s data or disrupt our services while you investigate.