Security
Security
How we approach privacy, isolation, and safe publishing while you build with Shipyard.
Private until you publish
Drafts and previews stay under your account. A project is only public when you choose to publish it. You decide when a version is ready for the outside world.
Isolated project workspaces
Builds run in isolated environments so one project’s preview does not bleed into another. Generated apps are scoped to your workspace and the collaborators you invite.
Account protection
Access to Shipyard requires authentication. Keep your credentials private, sign out on shared devices, and use a unique password for your account. Workspace hardening such as 2FA is covered in privacy and security settings.
Uploads and prompts
Files and prompts you attach are used to generate and refine your app. Avoid uploading production secrets, private keys, or unnecessary personal data. Prefer placeholders until you are ready to configure live credentials in a secure environment.
Published apps
When you publish, you are responsible for the content, forms, and data collection your app exposes. Lead forms and analytics should only collect what you need, and you should disclose that collection to your visitors when required.
Enterprise and disclosure
Larger teams can add SSO, audit logs, and a security review — see Enterprise. If you believe you found a security issue in Shipyard, email security@shipyard.app with enough detail for us to reproduce it. Please give us a reasonable window to investigate before public disclosure.