Security & Trust

How we host, encrypt, and disclose.

Bastion Security is published by Fusengine Sàrl (Vevey, Switzerland). This page summarises our current security posture and the compliance roadmap we are committed to publicly. Last reviewed on 24 May 2026.

Where we host

Customer data stays in Switzerland whenever technically possible. Cross-border transfers rely on the EU SCCs and the EU-US Data Privacy Framework.

Customer portal & marketing site

Switzerland — Vevey (Fusengine Sàrl infrastructure)

License API

Lemon Squeezy, Inc. (Merchant of Record, SOC 2-aligned)

Plesk extension runtime

Customer's own Plesk Node — no telemetry leaves the server unless explicitly attached to a support ticket

Encryption & secret handling

  • TLS 1.3 on every public endpoint, HSTS preload, OCSP stapling
  • License keys hashed with SHA-256 server-side, no plaintext storage
  • Backups encrypted at rest (AES-256), daily snapshots, 30-day retention
  • Secrets vaulted in environment-scoped stores, never in source code

Authentication & access

  • MFA required for every Fusengine staff account with production access
  • SSH: public-key only, password and root login disabled on production
  • Customer portal sessions: short-lived tokens, secure + httpOnly cookies
  • Principle of least privilege enforced for every internal role

Vulnerability disclosure

We follow coordinated disclosure. Please give us reasonable time to investigate and ship a fix before public release.

Coordinated disclosure

security@bastion-security.io — PGP key on request

RFC 9116 security.txt

https://bastion-security.io/.well-known/security.txt

Hall of fame

Researchers who report responsibly are credited on this page (with permission)

Scope

bastion-security.io · *.bastion-security.io · the Bastion Plesk extension binaries published on the Plesk Marketplace

Compliance roadmap

We publish our compliance commitments so customers can plan with us. Dates are objectives, not contractual guarantees.

  1. 2026 Q3 GDPR Data Processing Addendum (DPA) available on request for B2B
  2. 2026 Q4 Public bug bounty program launch
  3. 2027 Q1 SOC 2 Type I — audit in scope
  4. 2027 Q4 ISO 27001 — Stage 1 audit targeted