Security & Compliance Overview

Maelstrom AI builds downpipes and runs an ISMS aligned to ISO/IEC 27001:2022, covering downpipes and our support platform.

Public

Maelstrom AI builds downpipes. We run an Information Security Management System (ISMS) aligned to ISO/IEC 27001:2022. We are not certified today. We will pursue certification when it is commercially justified.

What is in scope

Two systems sit inside our ISMS.

downpipes is our no-custody backup product. It runs in the customer’s own Cloudflare account, under the customer’s own keys. Maelstrom never holds the customer’s backup data or keys.

Our support platform is internal. It runs on Cloudflare, in Maelstrom’s own Cloudflare account. It holds support conversations, customer email addresses and display names, attachments, support bundles and operator notes. Its technical logs record caller IP addresses and operator email addresses. See the Support Privacy Notice for how we handle this data.

Key security measures

downpipes

  • No-custody: Maelstrom never holds customer backup data or keys.
  • Post-quantum hybrid sealing: archives are sealed under customer-held keys.
  • Signed releases: the engine verifies each update against a pinned public key before it applies the update.
  • Pull-only updates: nothing is pushed to a customer’s account.
  • Source available: the engine, console and offline reader are published at github.com/downpipes-io.
  • Build provenance: each engine, console and offline reader release ships a SLSA provenance attestation and a Sigstore signature.

Edge platform

  • Cloudflare protects our infrastructure with DDoS protection, TLS and isolated execution environments.

Support platform

  • Authorised personnel reach it through an identity-aware access proxy that admits only named operator email addresses.
  • TLS protects data in transit. Cloudflare encrypts data at rest.
  • Retention limits apply, as the Support Privacy Notice sets out.

What we publish, and what we share on request

We publish thirteen documents in this Trust Centre: this overview; our Vulnerability Disclosure Policy; our Security Advisories; our Privacy Policy and its summary; our Terms of Service; our Cookie Policy and its summary; our Sub-Processors List; our Standard DPA, Enterprise DPA and SCC Addendum; and our Support Privacy Notice.

We share our detailed ISMS documents (scope statement, Statement of Applicability, risk register, policies, procedures and evidence) with customers, prospects and auditors on request, under a non-disclosure agreement. Email support@maelstrom.au.

Security contact

Report a security vulnerability to security@maelstrom.au. Our Vulnerability Disclosure Policy tells you how to report, and what we promise in return. Our security.txt file gives the same contact.

Security advisories

We publish security advisories on our Security Advisories page and in its RSS feed. That page also states when we notify customers of a compromise.


Document Information

  • Version. 2.2
  • Last Updated. 2026-09-29
  • Owner. ISMS Owner
  • Review Frequency. Annually
  • Classification. Public
  • Change (2.2). Added the Vulnerability Disclosure Policy and the Security Advisories page. Added the security@maelstrom.au contact.
  • Change (2.1). Corrected the build-provenance and support-access lines. Added the technical logs to the support-platform data.
  • Change (2.0). Rewritten.
  • Change (1.4). Editorial update.
  • Change (1.3). Editorial update.