StoryOS

Security

Your data, defensively designed.

The honest version of a security page: what we built, what we guarantee, and what we don't claim. The strongest control is one no vendor can revoke — the exit.

The export guarantee

Full-fidelity CSV export of any view or database, a complete REST API, and a one-click full-workspace ZIP (every schema, record, relation and attachment file) from Settings, on every plan including Free. If you cancel, your workspace degrades gracefully to Free — nothing is deleted, nothing is held hostage. Export is a right, not a feature tier.

The self-host escape hatch

StoryOS is AGPL-3.0 — the same product runs on your own server with one Docker command. Whatever happens to us, our pricing, or our infrastructure, the ultimate security answer stays open: take the code and your data and run it yourself.

Access that means something

A real role ladder (admin, member, contributor, viewer) with per-space and per-database grants. API tokens are scoped read / write / admin, and MCP agents are only offered the tools their token allows — a read-only token is a read-only agent.

Encryption in transit

All traffic to hosted StoryOS (app, API, MCP endpoint) is TLS-encrypted. Self-hosted deployments get the same via the bundled reverse proxy or your own (Cloudflare or Caddy-managed certificates are both documented).

Practices

Authentication

Email/password with verification and reset, optional Google sign-in, and OAuth for MCP connectors. Sessions and tokens are revocable; personal access tokens are shown once and scoped.

Auditability

Business plans include an audit log of workspace administration. The product itself is auditable in the strongest sense — the full source is public.

Backups (self-host)

Documented one-liners: pg_dump for the database plus an archive of the attachments volume. Upgrades run migrations idempotently.

No training on your data

We run no model training on workspace content. Connecting your own Claude or ChatGPT sends data to your AI provider under your agreement with them — by your choice, per request, never in bulk by us.

Cookieless website

This website runs no cookie-based tracking — analytics are cookieless and privacy-first, so there is no consent banner because none is needed.

Responsible disclosure

Found a vulnerability? Email security@storyos.dev — we read every report and credit fixes in the changelog.

GDPR & compliance, plainly

We operate on data-minimization principles: we store what the product needs (your account, your workspace content, operational logs) and nothing else. You can export everything and delete your account; erasure requests are honored. A Data Processing Agreement is available for Business and Enterprise customers — ask us.

What we don't claim: StoryOS is not yet SOC 2 or ISO 27001 certified — early-stage products that claim otherwise are telling you something about their honesty. Teams with hard certification requirements today should self-host inside their own certified infrastructure, which the AGPL license exists to make possible.

Trust the design, not the promises.

Start free — 30 days of Pro, no card. Export everything, always; leave whenever you want.