Security & procurement

We’re not a processor.

Bearing Pro runs inside your infrastructure. Your code, its analysis and its history never reach us — so most of a security questionnaire answers itself.

You askThe answer
DPA, sub-processors, data residencyWe’re not a processor. The software runs in your infrastructure; no code, analysis or findings ever reach us.
SOC 2 / ISO 27001 for the hosted serviceThere is no hosted service. Nothing of yours is held anywhere by us.
Telemetry, usage reporting, phone-homeNone. The server refuses any outbound request to a host you haven’t configured. The licence is verified offline.
What leaves your network?One artifact, once a year, sent by your operator: the renewal attestation. Repository identities hashed; nothing about people.
Source availabilityBearing Pro’s source is private, under a commercial licence. The component that touches your code — Bearing — is Apache 2.0 and public.
Source code escrowAvailable on request for larger agreements.
Air-gapped installsDesigned for them: an offline bundle and offline licence verification.

Verifying a download

Each Bearing Pro release ships a SHA256SUMS file signed with our release key. The public key is published with every release at github.com/IronMarten/bearing-releases. Before trusting it, check its fingerprint matches this one:

A109 6721 7B42 D606 DCA6 726C 09A0 77AB B48A D4AE

Bearing release signing <chris@ironmarten.com> · Ed25519 · expires 2028-09-30

$ gpg --import release.pub.asc
$ gpg --fingerprint "Bearing release signing"
$ gpg --verify SHA256SUMS.asc SHA256SUMS
$ sha256sum -c SHA256SUMS

The architecture

A self-contained single-file server for linux-x64 and win-x64, or the same binary as a container image. No database server, no broker: one process, one data directory.

Bearing runs in your CI and posts its output to the server you host. Digests and pull-request comments go only to the destinations you configure.

No per-person data

No author column on any table; no ranking; no per-person view, export or filter. Never a per-developer metric, by design.

Next step

Buying is an order form and a purchase order. No account, no checkout.