Trust Centre

Version: 1.0
Effective: September 1, 2026

Dependably Packages and Dependably StatusCheck are built and operated by MoonlitLabs Computing Ltd., a Canadian company.

This page summarizes how we secure our systems, our code, and the content customers place in Dependably Cloud, organized by control area. Where it describes Dependably Cloud, it describes what our customer agreements commit us to.

The documents this page summarizes:


Security program and policies

A written policy set governs information security, access control, change management, incident response, vendor management, risk management, data classification and handling, and application security testing. It is available on request under NDA. We self-assess our own build pipeline against NIST SSDF (SP 800-218) and our six-domain AI DevSecOps maturity framework, and we answer security questionnaires directly through support@dependably.ca.

Risk management

A written risk management policy governs how risks to customer content and to our own systems are identified, assessed, and treated. The maturity self-assessment of our own systems is available on request under NDA.

Endpoint security

Company endpoints run endpoint security monitoring that reports to a central console, and customer content is not stored on them. Production is reached only through individually named accounts, and deployments run through a scoped CI identity rather than a person's credentials.

Malware protection

Company endpoints run managed anti-malware protection, and customer content is not stored on them, so a compromised device cannot reach it.

Security awareness

Everyone who receives production access completes security awareness training first, and signs confidentiality and acceptable-use agreements that set out their responsibilities for customer content.

Access control

Access follows least privilege: a person or a process can reach only what its role requires. Production and administrative accounts for Dependably Cloud are protected with multi-factor authentication and least-privilege roles, and production access is recorded. Inside the service, multi-factor authentication is available to your administrators, and role-based access control scopes what each of your users can do.

Onboarding and offboarding

Before anyone receives production access, they sign confidentiality and acceptable-use agreements, complete security awareness training, and pass a background check. Access is removed at separation.

Hosting, data residency, and encryption

Dependably Cloud runs in AWS Canadian regions by default. Customer content and encrypted backups are stored in Canada, and content moves outside Canada only at your instruction. Compute runs in private networks behind a managed load balancer, with environments isolated from each other.

Data is encrypted in transit and at rest using industry standard modern encryption practices. Customer signing keys are stored encrypted, and the private keys you use to sign artefacts stay under your control.

Self-hosted editions run on your infrastructure under your controls. Nothing reaches us.

Tenant separation and deployment models

Dependably Cloud is multi-tenant by default, with logical separation between tenants enforced in code and covered by tests. A dedicated tenant and deployment in your own cloud account are scoped per agreement with Enterprise customers.

Monitoring and logging

Security-relevant events, including production access, are logged centrally. Logs are protected in transit and at rest, with automated alerting.

Secure development life cycle

Production repositories require review before merge. Third-party dependencies are pinned and verified. Automated static analysis, dependency, secret, and container scanning run in CI, and serious findings block a deploy. Our releases ship with SBOMs, signatures, and build attestations, from reproducible builds.

Dogfooding

Our own developer environments and CI install dependencies through Dependably Packages rather than the public registries, and refuses to build if that route is unavailable, so every package our build pulls has its checksum verified and is screened against the OSV vulnerability database before it reaches us. Third-party dependencies are pinned and verified, and dependency, container, and secret scanning run in CI with serious findings blocking a deploy.

Third-party management

A written vendor management policy governs which providers we use and how they are contracted. Providers that handle personal information do so under contract, and the Privacy Policy describes what each receives. Some providers, for payments, email, support tooling, error monitoring, and website analytics, operate in the United States.

Vulnerability management

Dependency, container, and secret scanning in CI find known vulnerabilities in what we build and ship. For what we miss, we run a coordinated vulnerability disclosure program with a safe harbour for good-faith research. Report through security@dependably.ca; scope, response targets, and safe harbour terms are at dependably.ca/security. We do not pay bounties, and we credit researchers publicly with their consent.

Business continuity

Encrypted backups are stored in Canada, and restore testing runs on a schedule.

Incident response

A written incident response policy, based on NIST SP 800-61, governs detection, containment, and recovery. Customers affected by a confirmed security incident involving their content are notified within the period set in the DPA, or sooner where the law requires.

Privacy and AI

We are a Canadian company, and Dependably Cloud defaults to Canadian hosting. Our Privacy Policy addresses PIPEDA, BC PIPA, GDPR, and Quebec Law 25 rights, and our DPA incorporates the EU Standard Contractual Clauses. We do not sell personal information, and we do not use marketing or cross-site tracking cookies.

Customer content is never used to train AI models, ours or anyone else's, and no third-party AI service receives it in any form. This is a binding term of our DPA; changing it would be a material change requiring customer notice.

Evidence available

Public on this site: the documents listed above. On request via security@dependably.ca, under NDA: the internal policy set and the maturity self-assessment of our own systems.


Contact

Every address is on the contact page at dependably.ca/contact. Security questions, evidence requests, and vulnerability reports go to security@dependably.ca.