Maelstrom AI Trust Centre

downpipes

Vendor Security and Assurance Pack

No-custody backup and disaster recovery for the Cloudflare data layer.

One document that answers a vendor security review: the architecture, the security posture, the control mappings, the shared-responsibility boundary, how support access works, and a pre-answered questionnaire. Free and public, with no contract, no NDA, and no login.

What does Maelstrom hold of your downpipes data?

Nothing.

No data. No keys. No tokens. The engine runs in your account, not ours.

  • No custody
  • Post-quantum hybrid
  • MIT offline reader
  • Fail-open licensing
  • ASVS 5.0 L1 and L2
Download the PDF Trust Centre
Version
1.4
Date
29 September 2026
Classification
Public
Status
Current
Applies to
downpipes
Owner
Maelstrom AI, support@maelstrom.au
Last change
1.4, 29 September 2026: security reports go to security@maelstrom.au, and the pack links to the vulnerability disclosure policy. The printed copy links to full web addresses.

The Trust Centre is the live source for this document. Publisher: Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust (ABN 61 633 823 792).

Trust at a glance

The whole pack, in one scan

Custody

Maelstrom holds none of your data, keys or tokens, in either posture.

See 03

Recovery

Restores with an MIT, offline, no-network reader. Two implementations, checked against each other in CI.

See 04

Posture

ASVS 5.0 self-assessed: no Level 1 or Level 2 requirement carries a gap verdict. Post-quantum hybrid seal. Hourly canary.

See 05

Scope

A supplier of self-hosted software, not a data processor or sub-processor.

See 01

SOC 2 and ISO 27001 are on the roadmap and stated as such, not claimed. Verify any of the above yourself: our security overview is published at maelstrom.au/trust, the offline reader is MIT-licensed, and the engine and console are source-available. Maelstrom operates the control plane and does not publish its source.

The short version

Scope us out

downpipes is self-hosted software that runs inside your own Cloudflare account. Through downpipes, Maelstrom AI holds none of your data, none of your encryption keys, and no standing access to your Cloudflare account. Support access is granted by you, time-boxed and revocable. There is no Maelstrom-operated system that stores or processes your downpipes backups.

For vendor risk, the accurate classification of Maelstrom AI in respect of downpipes is a supplier of self-hosted software, not a data processor or a sub-processor. For downpipes we process no personal data on your behalf; the software does, inside your tenancy, under your control. A compromise of Maelstrom cannot expose your downpipes backups, because we cannot read them, and your recovery does not depend on Maelstrom continuing to exist.

Paste this into your risk register: In respect of downpipes, Maelstrom AI is a supplier of self-hosted software, not a data processor or sub-processor for our data. It holds none of our data or keys, and no standing access to our Cloudflare account; the software runs in our own Cloudflare account, under our keys.

The product

What downpipes is, and how it runs

downpipes backs up Cloudflare Workers KV, D1, R2, Secrets Store and a wide range of Cloudflare configuration surfaces to storage you control, encrypted under keys only you hold. It has three parts: an engine (a Cloudflare Worker that runs in your account and writes encrypted archives to your destinations), a console (the management interface, also in your account), and an offline reader (a single open-source binary that restores an archive with no network and no vendor).

Your Cloudflare account

Sources: KV, D1, R2, Secrets Store, and other config surfaces

Engine

Runs in your account. Seals each archive under your keys.

Storage you control

Destinations: R2, S3 and more, under your keys

Restore runs the other way, with your keys, using the MIT offline reader. It needs no network and no vendor.

Maelstrom-operated and content-free: the control plane (a licence token and an optional beacon, fail-open) and the update channel (signed and read-only). On each cron tick the engine sends a GET for two static files at update.downpipes.io. Cloudflare adds a CF-Worker header that names the engine's zone. Unset UPDATE_CHANNEL_URL to stop the check. Neither service sees your backup data.

Figure 1. Data flow and trust boundary. Sources, engine and destinations are all in your account, under your keys.

Custody

No custody, by construction

Keys are generated in your browser during a guided ceremony. The break-glass private key, the one that can decrypt everything, never leaves your browser and lives offline, with you. The ceremony writes the keys the engine needs to your engine as Worker secrets, in your account. In the default, strict break-glass-only posture the engine holds no key that can decrypt an archive. If you opt in to an operational key, the engine holds it in your account (see below). Maelstrom does not hold any of your keys, in either posture, and a subpoena served on Maelstrom yields none of your backup data, because we hold none of it.

The residual disclosure worth reading twice: with an operational key, a decryption-capable private key sits in your in-account engine. It lets the engine read your archives with nobody present to supply a key: for scheduled restore tests, recovery drills, retention pruning and in-console restores. It is your key, in your engine, in your account. You choose the posture on the Keys screen and can change it later; the trade-off is stated in the product and in the ISMS. Maelstrom holds no key of yours in either posture.

Recovery

Recovery does not depend on us

The archive format (downpipe/0.1.0) is a public, normative specification with published conformance vectors. It is versioned, so a change to a byte-level rule makes a new format identity. There are two implementations: the Go reader, and the TypeScript engine, which is a byte-for-byte port of the Go reference. Shared known-answer vectors hold them to agreement, and a CI test proves that the Go reader restores what the engine writes. The offline reader is MIT-licensed: a single Go binary, with no telemetry, no SDK, and no network dependency. If Maelstrom disappeared tomorrow, you would still restore from your archives, with your keys, using an open tool. For a backup product, that is the definition of no lock-in.

Security posture

What is verifiable today

Every property below is either enforced by cryptography or verifiable by you.

ASVS 5.0, Levels 1 and 2

Self-assessed. No Level 1 or Level 2 requirement carries a gap verdict. Some requirements are partly met, and the accepted-risk register records each remaining exposure. The self-assessment and the register are free to download at downpipes.io/trust.

Post-quantum hybrid cryptography

X25519 with ML-KEM-1024 (FIPS 203) for key encapsulation; Ed25519 with ML-DSA-87 (FIPS 204) for signatures; AES-256-GCM for content; SHA-384 and HKDF-SHA-384. A break in either half alone does not break the seal.

Threat model and architecture

A written threat model, architecture and data-flow documentation, and a cryptographic bill of materials, all free to download at downpipes.io/trust.

Continuous integrity

An hourly canary flight proves byte-exact recovery across destinations; a hash-chained, tamper-evident audit log records gated actions, denials, role and configuration changes, and is exportable.

Access control

SSO through your own identity provider (OIDC, OAuth2 or SAML) or Cloudflare Access, WebAuthn passkeys, single-use recovery codes, and role-based access control with six built-in roles, custom roles and dual-control approvals. Standard in every edition, with no SSO surcharge.

Control mappings

What downpipes evidences

A product does not make you compliant; that obligation stays with you. What downpipes does is prove the backup-and-recovery control the way an assessor wants to see it: verified on each run, dated, and exportable. A mapping for each standard below is published at downpipes.io/compliance.

  • Essential Eight. Regular Backups, Maturity Levels 1 to 3.
  • ISM. ISM-1511, ISM-1515, ISM-1705 to 1708, ISM-1810 to 1814.
  • Australian regimes. APRA CPS 234 and CPS 230, SOCI Act and CIRMP, Privacy Act and APP 11.
  • International. DORA Articles 11 to 12 (segregated backups, defined RTO and RPO, integrity checks during recovery, at-least-annual restore testing); record-integrity checks that support SEC 17a-4 record-keeping (WORM retention is the customer's destination setting); NIS2 (business continuity and tested recovery).

We use downpipes to back up our own Cloudflare estate.

Shared responsibility

Who controls what

Because downpipes runs in your account, some controls are yours. This is the boundary an assessor needs to see.

Table 1. Shared-responsibility matrix.
ControlMaelstromCloudflareYou
downpipes software security ✓ – –
Vendor control plane and update channel ✓ – –
Operating the in-account engine and console – – ✓
Generating and safeguarding break-glass keys – – ✓
Destinations, retention and restore-test cadence – – ✓
Identity provider and operator access in your tenant – – ✓
Underlying edge compute and storage – ✓ –

Sub-processors

None in the data path

No third party, Maelstrom included, processes your backup data. downpipes adds no sub-processor, because no downpipes customer data is processed by or for Maelstrom. Maelstrom's own providers support our own systems, not your data. They include Cloudflare (compute, storage, access), Amazon Web Services (encrypted backup copies of our own systems, including the licence record), Stripe (Business self-serve billing) and GitHub (source control and CI/CD). Cloudflare and GitHub publish independent assurance reports (SOC 2 Type II, ISO 27001). The providers that process our commercial contact data are listed at downpipes.io/trust/sub-processors.

Operating practice

How support access works

Paid support holds no standing access to your account. When you ask for help and grant access, that access is requested in the open and approved by you, read-only and scoped to the task, time-boxed and revocable by you at any time, and written to your audit log. Between engagements, the vendor holds no access. Support operates within the no-custody model; it does not change it.

Certifications

What we hold, and what we do not

We do not currently hold SOC 2 or ISO 27001 certification. Both are on the roadmap; ask for current status and we will tell you the truth, including dates we are unsure of. Our ISMS is structured to ISO/IEC 27001:2022. Our security overview is published at maelstrom.au/trust; the policies, Statement of Applicability, risk register and data protection assessments are available to customers, prospects and auditors on request.

Certification is demand-gated: for a no-custody, self-hosted product there is essentially no vendor-held system to attest, and the architecture is a stronger answer than a report. Independent assessment reports and certificates, when held, are available under mutual NDA, at no charge. What we will not claim: there is no Essential Eight certification, for anyone, and IRAP assessors assess systems, not products.

Legal and contractual

The DPA, and what the paid tiers add

downpipes is free to run. The paid tiers buy a relationship, never the software.

  • Data Processing Agreement. A signable DPA is published at maelstrom.au/trust. Because downpipes is no-custody, the DPA covers support data. It states why downpipes adds no sub-processor for your infrastructure data.
  • Enterprise adds (priced separately, see downpipes.io/pricing): a support response SLA, a named contact, a counter-signed DPA on our standard paper, your own security questionnaire completed under our signature, and a set number of vendor-assessment calls each year.
  • Custom covers contracts on your paper, bespoke security and liability terms, formal audit support, deployment and recovery services, and extended-hours and on-call critical-incident response by arrangement.

Sample questionnaire

The common questions, pre-answered

Enterprise customers get their own security questionnaire, such as a CAIQ or SIG-lite, completed under our signature; this sample lets you pre-clear the basics today.

Where is customer data stored?
In your own Cloudflare account, and the destinations you choose. Maelstrom stores none of it.
Is data encrypted at rest and in transit?
Yes. Archives are sealed with post-quantum hybrid encryption under your keys; transport is over TLS.
Who can access customer data?
Only you. Maelstrom cannot decrypt your archives.
Do you use sub-processors for customer data?
No.
How is access controlled?
SSO, passkeys, role-based access control with six built-in roles, dual-control approvals, and a hash-chained audit log.
Do you run a vulnerability disclosure process?
Yes. Report to security@maelstrom.au, under our Vulnerability Disclosure Policy at maelstrom.au/trust/security/disclosure. We work to CVSS-based remediation targets (Critical 2 business days, High 7 days, Medium 30 days, Low 90 days).
Do you test recovery?
Yes. An hourly canary, plus signed restore-test drills.
What is your breach-notification commitment?
Maelstrom holds none of your downpipes backup data, so a Maelstrom incident cannot breach your backups. For personal information we do hold, we follow the Australian Notifiable Data Breaches scheme: we notify the OAIC and affected individuals as soon as practicable. We email the people whose contact details we hold, such as paid-plan contacts. For anyone we cannot contact directly, we publish the statement on maelstrom.au. Enterprise customers are also notified under their agreement.
Is the software auditable?
The engine and console are source-available under the Elastic License 2.0; the offline reader is MIT-licensed. Maelstrom operates the control plane and does not publish its source.
What happens if we stop paying, or you disappear?
Nothing to your backups or restores. Licensing is fail-open; the product keeps running as Community, and recovery uses the open offline reader.

Next

Where to go next

Everything here is free and verifiable, with a live source for each.