Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Good question. We are based on Chromium, the open-source Web browser project started by Google that powers Google Chrome. Therefore on that part the same security model as Chrome applies. On the data side, most information is stored locally on your computer. Very few information is actually stored in our database therefore reducing the risk. For instance we do not store any username, passwords or token you use to login into your app in our database.

Now we haven't yet worked directly with infosec departments so we are well aware that there is still work to be done for us to be fully vetted.

As for adding an internal Jira instance, you can do that directly from the app store in the Station app. Click on the "+" button at the bottom right of the screen and you can request a custom app (visible either just to you or your entire team).



When we add a custom app, do you see those URLs?

Remember that even a URL could contain confidential information, such as a project planning board for a corporate takeover or new product launch.


Good point, I definitely understand the concern. We only see the main domain, whatever comes after the "/" in the URL isn't visible to us or anyone else.


how do you handle chromium updates? Do you produce a new release the same day, the same week, something else?


We get Chromium updates when we upgrade to a new version of Electron. We rely on Electron integrating the new version (typically there is always a delay) to be up to date.


Could I email you a Vendor Security Questionnaire to see if we can try it out?


Yes definitely that would be interesting. You can e-mail it at hello@getstation.com Thanks




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: