Package access
You can limit a download key to a registry, scope, or selected packages. The key cannot publish. You can revoke it at any time.
We use optional analytics to understand visits and advertising measurement to see what leads to signups. Choose what you allow. Privacy policy
Your browser sends a Global Privacy Control signal, so advertising measurement stays off.
We help teams share private npm packages with employees or customers. This page explains our security controls, service providers, and data locations.
PrivateNPM.com is the business name of Paraply Ventures AS. The company is based in Norway. Our shared service manages accounts and package access in the US. Package servers run in the US, Europe, and Singapore.
You can limit a download key to a registry, scope, or selected packages. The key cannot publish. You can revoke it at any time.
Engineers receive production alerts 24 hours a day. They respond to incidents that affect customers.
Our main app and primary database are in Ashburn, Virginia. Tigris stores package files across regions. Read all data locations.
These controls describe the current product and deployment. For more detail, email [email protected].
The public HTTPS service and registry run as separate apps. The web app and background workers use separate process groups.
The registry app uses Fly's private network. A public service handles HTTPS for registry domains.
The app uses one database role for requests and another for schema changes. A failed schema change stops deployment.
The web app, background worker, registry, and public HTTPS service each have health or readiness checks.
The app limits database requests to one organization. PostgreSQL row-level security checks this limit in each transaction.
Download keys cannot publish. You can limit a key to a registry, scope, or selected packages. You can revoke it at any time.
We store passwords as Argon2id hashes. Members can use passkeys or two-factor sign-in. We also support roles, SSO, and SCIM.
We store hashes of access keys, not the keys themselves. We encrypt saved integration secrets with an installation key.
You cannot change a published version. If you unpublish it, the registry keeps a record. A retry cannot publish different content for the same request.
If the registry cannot confirm access, it refuses the download. It does not fetch private package names from public npm.
Browser pages use a Content Security Policy and checks for cross-origin requests. Webhooks and identity connections cannot call private network addresses.
Engineers receive production alerts at all hours. They respond to incidents that affect customers.
Alerts cover outages, high error rates, slow requests, database pressure, failed jobs, email and webhook delivery, and unusual sign-in activity.
We run static checks, builds, and Go and browser tests before each push. Deployments use fixed action versions and separate tokens.
Our production runbook gives steps for database and file recovery. It also covers encryption-key rotation.
The audit log records changes to packages, keys, members, and plans. Administrators can set how long audit and other event records stay.
When you delete an account or organization, we remove active records and start file cleanup. Legal and backup retention can still apply.
Stripe handles card details when billing is enabled. PrivateNPM.com does not store full card numbers.
You can change your choices for analytics and ad measurement. We do not send package contents or access keys to these services.
These companies help us run the service. Some handle your data only if you use a related feature or book a demo.
Role: Runs the app, registry, workers, and HTTPS endpoints.
Data: Requests, account data, and registry data.
Role: Hosts the PostgreSQL database in Ashburn, with US replicas and backups.
Data: Accounts, organization settings, package data, access records, and audit events.
Role: Stores package archives and files across regions.
Data: Published packages and uploaded files.
Role: Stores registry certificate data in Redis in Ashburn, with US replicas and backups.
Data: Registry hostnames and certificate data.
Role: Provides DNS and proxies the public website.
Data: DNS records, query data, and public website requests.
Role: Sends account and notification email.
Data: Recipient addresses and message content.
Role: Collects application errors.
Data: Error reports that can include request data.
Role: Handles billing and card payments.
Data: Customer, subscription, invoice, and payment data.
Role: Measures website visits and signup activity.
Data: Page visits and conversion events.
Role: Measures conversions from ads.
Data: Ad click identifiers and conversion data.
Role: Books demos with an engineer.
Data: Details you enter when you book.
Read our privacy policy to learn how we use personal data. For questions about data locations, email [email protected].
The main app, which manages accounts and package access, runs in Ashburn, Virginia. The primary PostgreSQL database also runs there. The database has replicas and backups in Newark and Dallas.
Upstash stores registry certificate data in Ashburn, with replicas and backups in the US. Package servers run in the US, Europe, and Singapore. They contact the US app to verify access. Tigris stores package files across regions.
No. The current shared service uses a US app and database. Tigris stores files across regions. An EU-only service needs separate EU systems for accounts, packages, backups, email, logs, and support.
Resend stores email content and delivery logs in the US. We must replace it for an EU-only service. Email engineering about an EU-only service. We will agree on the data boundary before we offer it.
Public web and registry connections use HTTPS. We store passwords as Argon2id hashes and encrypt saved integration secrets. We use database row-level security to separate organizations. Read more about product security.
We keep account details, security records, organization settings, usage records, and logs that we need to run the service. Your privacy choice controls optional site measurement. For more detail, read our privacy policy.
No. If you use Stripe billing, you enter card details with Stripe. We keep the customer and subscription data that we need to manage your plan.
Alerts reach engineers 24 hours a day. We respond to incidents that affect customers. The independent status page is not live yet. For the current availability commitment, read our terms of service. We do not publish an uptime percentage or recovery target yet.
We do not have a SOC 2 or ISO 27001 report for PrivateNPM.com. We do not have a public penetration test report. Email the security team with your questionnaire. We will answer it directly.
Email [email protected]. Tell us which feature is affected, how to reproduce the issue, and what can happen. Use your own accounts. Do not access other customers' data or disrupt the service. We do not offer a bug bounty.
Send security reports by email. Contact engineering about package access, incidents, or data locations. You can also book a demo with an engineer.