PackMyApp
Features Pricing Docs

Security & Trust

You give PackMyApp access to your endpoint management. Here is exactly how we treat that responsibility.

How PackMyApp accesses your tenant

  • You sign in with your own Microsoft Entra ID account. There are no PackMyApp passwords for your tenant, and we never see or store your Microsoft credentials.
  • Intune actions run on delegated tokens. Deployments, group changes, and inventory reads execute with the permissions of the signed-in user, scoped by Microsoft to that user's tenant session. PackMyApp cannot reach into tenants you did not link.
  • You can disconnect at any time. Unlinking a tenant removes the stored link; access tokens expire on Microsoft's schedule.

What we store — and what we don't

  • We store: your account identity (name, email, Entra object id), tenant links you create, deployment and update metadata (which app, version, group, when), and configuration you enter (templates, auto-update schedules).
  • We do not store: your Microsoft credentials, the contents of your devices, or your custom installers — PackMyApp Forge packages your own applications locally on your machine and uploads them directly to your Intune tenant, never to PackMyApp servers.
  • Payment data is handled entirely by Stripe; card numbers never touch PackMyApp systems.

Where it runs

  • Application hosted on Microsoft Azure in West Europe; database on Azure Database for PostgreSQL in North Europe. Your data stays in the EU.
  • HTTPS-only with TLS 1.2+; security headers (Content-Security-Policy, X-Frame-Options: DENY, nosniff, Referrer-Policy) are enforced and continuously verified by our own health-check suite.
  • Point-in-time database backups with 7-day retention.

How it's built to fail safely

  • Fault isolation by design: every feature runs as its own engine. If one component breaks, it is disabled on its own — the platform, and your deployments, keep running.
  • Admin access requires MFA. Platform administration is separated from customer accounts and protected with TOTP-based multi-factor authentication.
  • Continuous verification: over 130 automated health checks (including security-header and tenant-isolation checks) can be run on demand, and every release passes linting, a full test suite, dependency CVE scans (pip-audit, npm audit, .NET scan), and static security analysis (bandit) before it can deploy.

Transparency

  • Live service status: packmyapp.com/status
  • Release notes ship with every version — typically multiple releases per week.
  • Questions, disclosures, or security reports: contact us. Security reports get priority handling.

We don't claim certifications we don't hold. As PackMyApp grows, formal audits (such as SOC 2) are on the roadmap — until then, this page states plainly what we do.

© 2026 PackMyApp — All rights reserved.

Privacy Policy Terms of Service Security Contact