Trust

Trust and security at Barrion

You're about to let us test your app and hand us a login for it. Here's where that data lives, how we keep your credentials safe, and what our agents will and won't do on your systems.

Data

Where does your data live?

Stored and hosted in Sweden. AI processing in the EU. These are the subprocessors that handle it.

SubprocessorPurposeRegion
GoogleHosting and database, sign-in, website analytics, email and office toolsSweden (hosting and customer data), other services EU and global
OpenRouterAI model routing for pentestsEU
MailgunTransactional emailEU
StripePayments and billingGlobal
SentryError trackingEU (Germany)
PostHogProduct analyticsEU
CookieYesCookie consentEU
SlackNotificationsGlobal
Microsoft TeamsNotificationsGlobal
CloudflareDNSGlobal
Credentials

How do we protect your test credentials?

To test behind a login, we need an account on your app. Anything you add for that is encrypted before it's stored, with AES-256-GCM envelope encryption.

In practice, each credential gets its own freshly generated 256-bit key. That key encrypts the credential, and a separate master key encrypts the key. What sits in the database is ciphertext plus a wrapped key, so a copy of the database alone doesn't give up your passwords. GCM also detects tampering: a modified record fails to decrypt instead of returning altered data.

We recommend a dedicated test account rather than a real user's login.

Safety

How do pentests stay safe?

A pentest sends real requests to a live app, so the limits are set before it starts and checked while it runs.

  • ✓You prove you own the domain, then approve the targets, credentials and off-limits paths. No traffic goes out before that.
  • ✓Agents only test in-scope hosts, and never private or internal IP ranges. Every action an agent proposes passes a policy check before it runs.
  • ✓Requests are rate-limited per host, with a conservative default, so a run doesn't pile load onto your app.
  • ✓Agents are told to use no destructive payloads, no denial of service, no data exfiltration and no persistence.
  • ✓If an agent changes state to show impact (a password reset or a mass-assignment test, say), it's told to undo the change and note it in the finding.
  • ✓Endpoints that send email or SMS, or create accounts, get a small request budget for the whole run, so your users' inboxes don't fill up.
  • ✓Each engagement runs in its own isolated sandbox container, with its capabilities dropped and no access to the host network.

You can point any test at staging, a preview or a pre-launch environment instead of production.

Access

Who can see your results?

Pentest runs and reports belong to your account, and every request for them is checked against it. From Standard level up, a Barrion security engineer reviews your findings before the report is released.

Disclosure

Found a vulnerability in Barrion?

Email contact@barrion.io. The same address is in our security.txt. Reports in English or Swedish are both fine.

A useful report includes:

  • ✓The affected URL or endpoint
  • ✓Steps to reproduce it, with the requests you sent
  • ✓What an attacker could do with it
  • ✓How we can reach you with follow-up questions

Please test only against your own account and data, don't degrade the service for other customers, and give us a fair chance to fix the issue before you publish it.

Company

Who is behind Barrion?

Barrion is run by Barrion AB, a Swedish company with organisation number 559569-0917. Prices, pentest levels and coverage are on the facts page.

Security questions about Barrion? Ask us.

Tell us what your security review needs to know and someone on the team will answer it.