Security
How ProductOwner protects your data, and how to report a security problem.
Report a problem: email [email protected]. Please give us a chance to fix it before telling others; we'll answer within two working days and credit you if you like.
Your data stays with you
- Self-hosted: ProductOwner and its database run on your server or private cloud. The app sends no telemetry or usage data to us.
- Works without internet once installed (an offline install is available); only services you connect are contacted.
Signing in
- Passwords are stored as scrypt hashes, never in plain text. Repeated wrong passwords lock the account for a while.
- Sessions use random tokens; only their hashes are stored. Signing out ends the session.
- Company sign-in with OpenID Connect (Microsoft Entra ID, Google Workspace, Okta): authorization code flow with PKCE; the ID token's signature, issuer, audience, expiry and nonce are checked. Only invited people get in.
Who sees what
- Roles per project (client, product owner, developer, tester, DevOps, admin) decide what each person can see and do, checked on the server.
- Clients only see their own requests and screens, never the team's internal comments.
Secrets and traffic
- Saved secrets (code host tokens, email password, sign-in client secret) are encrypted with AES-256-GCM using a key you set (PO_SECRET), kept out of the database.
- HTTPS by default: the installer sets up certificates automatically (Let's Encrypt or your own).
- Licence files are signed (Ed25519); the app only accepts licences we signed.
Running it safely
- One-command backups and restore, and updates that keep your data.
- Every change to work items is recorded as an event with who did it and when.
- Dependencies are checked and a software bill of materials (SBOM) is published with each release.