Skip to content
Back to PrivateNPM.com PrivateNPM.comTrust Center

PrivateNPM.com Trust Center

We help teams share private npm packages with employees or customers. This page explains our security controls, service providers, and data locations.

At a glance

PrivateNPM.com is the business name of Paraply Ventures AS. The company is based in Norway. Our shared service manages accounts and package access in the US. Package servers run in the US, Europe, and Singapore.

Package access

You can limit a download key to a registry, scope, or selected packages. The key cannot publish. You can revoke it at any time.

Monitoring

Engineers receive production alerts 24 hours a day. They respond to incidents that affect customers.

Data location

Our main app and primary database are in Ashburn, Virginia. Tigris stores package files across regions. Read all data locations.

Security controls

These controls describe the current product and deployment. For more detail, email [email protected].

Infrastructure security

  • Separate services

    The public HTTPS service and registry run as separate apps. The web app and background workers use separate process groups.

  • Private registry app

    The registry app uses Fly's private network. A public service handles HTTPS for registry domains.

  • Separate database roles

    The app uses one database role for requests and another for schema changes. A failed schema change stops deployment.

  • Health checks

    The web app, background worker, registry, and public HTTPS service each have health or readiness checks.

Product security

  • Organization isolation

    The app limits database requests to one organization. PostgreSQL row-level security checks this limit in each transaction.

  • Separate publishing and download keys

    Download keys cannot publish. You can limit a key to a registry, scope, or selected packages. You can revoke it at any time.

  • Account sign-in

    We store passwords as Argon2id hashes. Members can use passkeys or two-factor sign-in. We also support roles, SSO, and SCIM.

  • Stored secrets

    We store hashes of access keys, not the keys themselves. We encrypt saved integration secrets with an installation key.

  • Published versions

    You cannot change a published version. If you unpublish it, the registry keeps a record. A retry cannot publish different content for the same request.

  • Access checks

    If the registry cannot confirm access, it refuses the download. It does not fetch private package names from public npm.

  • Browser and webhook safety

    Browser pages use a Content Security Policy and checks for cross-origin requests. Webhooks and identity connections cannot call private network addresses.

Operations

  • Incident response

    Engineers receive production alerts at all hours. They respond to incidents that affect customers.

  • Monitoring

    Alerts cover outages, high error rates, slow requests, database pressure, failed jobs, email and webhook delivery, and unusual sign-in activity.

  • Release checks

    We run static checks, builds, and Go and browser tests before each push. Deployments use fixed action versions and separate tokens.

  • Recovery procedures

    Our production runbook gives steps for database and file recovery. It also covers encryption-key rotation.

Data and privacy

  • Audit log

    The audit log records changes to packages, keys, members, and plans. Administrators can set how long audit and other event records stay.

  • Deletion

    When you delete an account or organization, we remove active records and start file cleanup. Legal and backup retention can still apply.

  • Card payments

    Stripe handles card details when billing is enabled. PrivateNPM.com does not store full card numbers.

  • Site analytics

    You can change your choices for analytics and ad measurement. We do not send package contents or access keys to these services.

Service providers

These companies help us run the service. Some handle your data only if you use a related feature or book a demo.

  • Fly.io

    Core service

    Role: Runs the app, registry, workers, and HTTPS endpoints.

    Data: Requests, account data, and registry data.

  • PlanetScale

    Core service

    Role: Hosts the PostgreSQL database in Ashburn, with US replicas and backups.

    Data: Accounts, organization settings, package data, access records, and audit events.

  • Tigris

    Core service

    Role: Stores package archives and files across regions.

    Data: Published packages and uploaded files.

  • Upstash

    Core service

    Role: Stores registry certificate data in Redis in Ashburn, with US replicas and backups.

    Data: Registry hostnames and certificate data.

  • Cloudflare

    Core service

    Role: Provides DNS and proxies the public website.

    Data: DNS records, query data, and public website requests.

  • Resend

    Account email

    Role: Sends account and notification email.

    Data: Recipient addresses and message content.

  • Sentry

    Error reports

    Role: Collects application errors.

    Data: Error reports that can include request data.

  • Stripe

    Paid plans

    Role: Handles billing and card payments.

    Data: Customer, subscription, invoice, and payment data.

  • Umami

    Optional analytics

    Role: Measures website visits and signup activity.

    Data: Page visits and conversion events.

  • Google

    Optional ads

    Role: Measures conversions from ads.

    Data: Ad click identifiers and conversion data.

  • Cal.com

    Demo booking

    Role: Books demos with an engineer.

    Data: Details you enter when you book.

Read our privacy policy to learn how we use personal data. For questions about data locations, email [email protected].

Questions and answers

Where do you process my data?

The main app, which manages accounts and package access, runs in Ashburn, Virginia. The primary PostgreSQL database also runs there. The database has replicas and backups in Newark and Dallas.

Upstash stores registry certificate data in Ashburn, with replicas and backups in the US. Package servers run in the US, Europe, and Singapore. They contact the US app to verify access. Tigris stores package files across regions.

Can you keep all customer data in the EU?

No. The current shared service uses a US app and database. Tigris stores files across regions. An EU-only service needs separate EU systems for accounts, packages, backups, email, logs, and support.

Resend stores email content and delivery logs in the US. We must replace it for an EU-only service. Email engineering about an EU-only service. We will agree on the data boundary before we offer it.

How do you protect accounts and keys?

Public web and registry connections use HTTPS. We store passwords as Argon2id hashes and encrypt saved integration secrets. We use database row-level security to separate organizations. Read more about product security.

What personal data do you collect?

We keep account details, security records, organization settings, usage records, and logs that we need to run the service. Your privacy choice controls optional site measurement. For more detail, read our privacy policy.

Do you store payment card numbers?

No. If you use Stripe billing, you enter card details with Stripe. We keep the customer and subscription data that we need to manage your plan.

What happens during an outage?

Alerts reach engineers 24 hours a day. We respond to incidents that affect customers. The independent status page is not live yet. For the current availability commitment, read our terms of service. We do not publish an uptime percentage or recovery target yet.

Do you have a security certification or penetration test report?

We do not have a SOC 2 or ISO 27001 report for PrivateNPM.com. We do not have a public penetration test report. Email the security team with your questionnaire. We will answer it directly.

How do I report a security issue?

Email [email protected]. Tell us which feature is affected, how to reproduce the issue, and what can happen. Use your own accounts. Do not access other customers' data or disrupt the service. We do not offer a bug bounty.

Contact us

Send security reports by email. Contact engineering about package access, incidents, or data locations. You can also book a demo with an engineer.