How it runs, in plain words.
This page lists what is true about our infrastructure today, and what is not done yet. No badges we haven't earned, no certificates we don't hold.
One server, Hetzner, GermanyCloudflare in frontAES-256-GCM secretsNightly backups
What is true today. What isn't done yet is listed below.
The infrastructure
Small on purpose. One box we control, a CDN in front, and nothing rented by the hour that can vanish overnight.
The server
- One Hetzner dedicated server in Germany. Ryzen 7, 64 GB RAM, two 1 TB NVMe drives in a RAID 1 mirror.
- Disks. One drive dropped out in August and was restored on 29 September. The mirror kept running on the other drive throughout.
- Coolify runs the apps on the box. Each app is its own container with its own storage.
The network
- Cloudflare sits in front of everything: DNS, CDN, and TLS. Encryption ends at their edge.
- The server itself is not directly reachable. Traffic arrives through a Cloudflare tunnel.
One engine per customer
The cloud version does not pool customers into one shared database.
Secrets and files
Billing keys and webhook secrets are sealed at rest with AES-256-GCM under a key that lives only on the server. Tax form files are sealed per row, tied to their record, and never served from the static folder.
We do not claim full-disk encryption. The drives are not encrypted, and we would rather say that than hint otherwise.
Who processes what
- Stripe takes payments.
- Cloudflare handles DNS, the CDN, site hosting, and email for the license shop.
- Hetzner runs the server.
- Resend sends cloud account emails.
Backups, honestly
Nightly, the last 7 kept, one per database and volume. On the same server.
That last part is the weak spot, and we say so. Backups on the same box protect against a bad deploy or a broken database. They do not protect against the box itself being lost.
Off-box backups are not set up yet. When they are, this page changes the same day. Until then, self-hosters who want geographic safety should run their own: the backup command writes a single compacted file you can copy anywhere.
Not done yet
- Off-box backups to separate storage
- A tested restore from those backups
- A public status page
- A security@ mailbox
- SOC 2. We have no audit and claim none.
Trust questions
Where does my data physically live?
On one dedicated Hetzner server in Germany. Cloud workspaces are isolated per customer: each has its own engine process and its own database file on that server.
What happens if a drive fails?
The two NVMe drives mirror each other. In August one dropped out and the server kept running on the other. It was restored on 29 September. A full guide for self-hosters on backups and restores ships with the software.
Do you have SOC 2 or an audit?
No. No pen test, no SOC 2, no bug bounty either. What we do have: a published threat model, the security tests that run on every commit, and a page that says exactly what we store. When an audit exists, it goes on this list.
Can I keep the data myself instead?
Yes. Self-host runs on your own server with SQLite in one file. Your data never touches ours. The $99 license covers exactly that.
Who do I contact about a security issue?
Email support@affiliatetracking.co with Security in the subject. The security page lists what to include and how we handle reports.
Trust what you
can verify.
Hold the money before payout, check the books yourself, keep the data on your own server. Self-host is $99 once.