Security & procurement
We’re not a processor.
Bearing Pro runs inside your infrastructure. Your code, its analysis and its history never reach us — so most of a security questionnaire answers itself.
| You ask | The answer |
|---|---|
| DPA, sub-processors, data residency | We’re not a processor. The software runs in your infrastructure; no code, analysis or findings ever reach us. |
| SOC 2 / ISO 27001 for the hosted service | There is no hosted service. Nothing of yours is held anywhere by us. |
| Telemetry, usage reporting, phone-home | None. The server refuses any outbound request to a host you haven’t configured. The licence is verified offline. |
| What leaves your network? | One artifact, once a year, sent by your operator: the renewal attestation. Repository identities hashed; nothing about people. |
| Source availability | Bearing Pro’s source is private, under a commercial licence. The component that touches your code — Bearing — is Apache 2.0 and public. |
| Source code escrow | Available on request for larger agreements. |
| Air-gapped installs | Designed for them: an offline bundle and offline licence verification. |
Verifying a download
Each Bearing Pro release ships a SHA256SUMS file signed with our release key.
The public key is published with every release at
github.com/IronMarten/bearing-releases. Before trusting it,
check its fingerprint matches this one:
A109 6721 7B42 D606 DCA6 726C 09A0 77AB B48A D4AE
Bearing release signing <chris@ironmarten.com> · Ed25519 · expires 2028-09-30
$ gpg --import release.pub.asc
$ gpg --fingerprint "Bearing release signing"
$ gpg --verify SHA256SUMS.asc SHA256SUMS
$ sha256sum -c SHA256SUMS The architecture
A self-contained single-file server for linux-x64 and win-x64, or
the same binary as a container image. No database server, no broker: one process, one data
directory.
Bearing runs in your CI and posts its output to the server you host. Digests and pull-request comments go only to the destinations you configure.
No per-person data
No author column on any table; no ranking; no per-person view, export or filter. Never a per-developer metric, by design.
Next step
Buying is an order form and a purchase order. No account, no checkout.