ClusterPilot Trust Center
See what ClusterPilot protects and where the limits are.
Find information about architecture, security, release scope, software supply chain, data, recovery and security reporting.
- Deployment
- Customer-hosted
- External control plane
- Not required
- Release scope
- Publicly documented
- Website profiling
- None
Technical information
Start with what is already documented.
We do not replace missing proof with empty promises or implied certifications.
Deployment and data boundary
Where the control plane, PostgreSQL, artifacts, agents, credentials, registries and target systems operate.
↗02 · SecurityIdentity and privileged execution
Authentication, authorization, secret handling, destructive intent, audit and safe failure.
↗03 · ReleaseCapability status and compatibility
Supported paths, default gates, known limits and the evidence required for environment approval.
↗04 · Supply chainImmutable distribution
Digests, checksums, signatures, SBOM, provenance and customer-registry or restricted-network paths.
↗05 · RecoveryBackup and support handoff
Recovery units, operational evidence, redacted bundles and structured incident escalation.
↗06 · PrivacyPublic website data handling
No analytics, advertising or profiling scripts; public provider and privacy information.
↗Document capability and compatibility; identify artifacts; maintain controls, error contracts and operator guidance.
Own identity, network, provider, registry, credentials, backups, access policy and production approval.
Validate the real environment; define success, recovery, evidence and contractual support boundaries.
Security report
Report a suspected security issue directly.
Include the version or page, affected component, possible impact and safe steps to reproduce the issue. Do not send real credentials, customer data or harmful content in the first message.