How Caisson secures the controls it generates and this site itself — fail-closed RLS, a resolve-and-recheck SSRF guard, timing-safe secret comparison — with the residuals stated, not hidden.
Availability, subprocessors, and the security story.
What a procurement review checks, in one place: live and historical availability for the surfaces a Caisson deployment depends on, the third parties that process data for the Caisson service, the shipped security posture, and a name to email when you need more.
A live status page.
We publish live status and incident history for the public surfaces a Caisson deployment resolves against. The page shows measured availability — what actually happened — never a promised number.
Monitored surfaces
- The website and buyer dashboard
- The registry (module resolution)
- The license service
- The docs assistant
The posture, stated precisely.
Caisson generates the evidence a security review asks for; it is not an auditor, and never claims to be. The shipped story lives on these pages — read them, run the controls, and put your own reviewer's name on the result.
The proof artifacts a review asks for, already shipped: OSCAL conformance in CI, the standards gate, byte-identical registry provenance, real S3 Object-Lock WORM verification, and the append-only audit chain.
The technical controls the SOC 2 and HIPAA frameworks require, and the boundary between what Caisson ships and what stays your organization's responsibility.
Who you buy from, how Paddle handles invoicing as merchant of record, how to request documentation, and how to report a vulnerability.
Who processes what.
Caisson the product runs inside your own infrastructure, and your application data stays there. The services below process data for the Caisson service itself — this website, checkout, email, support, monitoring, and inference — not your application data.
| Processor | Purpose | Data categories | Region |
|---|---|---|---|
| Railway | Hosts the Caisson website, buyer dashboard, and the license, registry, docs, and support services, along with their Postgres databases. |
| United States |
| Cloudflare | DNS, reverse proxy, WAF, edge Workers (the registry read path), and R2 object storage. |
| Global edge network |
| Paddle | Merchant of record: checkout, payment processing, tax, and receipts. Payment details are collected and held by Paddle and never reach Caisson. |
| Global (United Kingdom) |
| Resend | Delivery of transactional and product-update email. |
| United States |
| Amazon SES | Secondary delivery path for transactional email. |
| United States |
| PostHog | Product analytics for the buyer dashboard. |
| United States |
| Plausible | Cookieless site analytics for the marketing pages. |
| European Union |
| Grafana Cloud | Observability: metrics, logs, and traces from the Caisson fleet. |
| United States |
| Better Stack | Uptime monitoring and the public status page. |
| United States |
| OpenRouter | AI inference for the documentation assistant and the support bot. |
| United States |
| GitHub | Source hosting and continuous integration. |
| United States |
| Discord | The support and community server. |
| United States |
This list is a maintained artifact: a new external service that processes data for the Caisson service lands a row here in the same change that introduces it.
For a security questionnaire, a data-flow diagram, or a vulnerability report, email [email protected]. For contracts, tax, or entity documents, email [email protected].