ShardlyHQ
Responsibility

The commitments we are prepared to be held to.

Energy, hardware lifecycle, data protection, security disclosure and governance — written plainly, with no certification logos standing in for the actual commitment.

EU
Data residency

Workloads, backups and logs never leave the European Union.

100%
Renewable supply

Contracted at every facility; the mix is published, not offset.

24h
Disclosure ack

Security reports are acknowledged within one day, always.

0
Outside shareholders

Nobody's return depends on a decision that is bad for customers.

01Commitments

Four areas, each with something specific behind it.

A commitment that cannot be checked is a slogan. Each of these has a practice attached that somebody outside the company could verify.

Energy

Our facilities run on contracts for renewable supply, and we publish the mix rather than a carbon-neutral badge bought from a broker. Capacity is planned so machines run loaded instead of idling in reserve.

Hardware lifecycle

Owning the hardware means we also own what happens to it. Nodes are run to end of useful life, then wiped to a documented standard and resold or recycled — never landfilled and never sold with data on them.

Data protection

Workloads, backups and logs stay inside the European Union. We collect the minimum needed to run and bill the service, and we will tell you exactly what that is if you ask.

Governance

Founder-owned with no outside shareholders. There is no board to satisfy and nobody whose return depends on a decision that would be bad for customers.

02Security disclosure

Report it. We will not come after you.

If you find a vulnerability in Shardly’s systems, write to hello@shardlyhq.xyz with “Security” in the subject line. You will get a human acknowledgement within 24 hours and a substantive reply within five working days.

Our side of the deal. We will not pursue legal action against anyone acting in good faith under this policy, we will keep you updated while we fix the issue, and we will credit you publicly unless you would rather we did not.

Your side. Give us reasonable time before publishing, do not access or modify data belonging to other customers, and do not run tests that degrade the service for anyone else.

In scope

shardlyhq.xyz, the platform’s control plane and API, and the infrastructure that serves customer workloads.

Out of scope

Findings in customer-uploaded code, social engineering of staff, physical access attempts, and volumetric denial of service. Report those as ordinary tickets instead.

We do not run a paid bounty yet and we would rather say so than imply one. Where a report leads to a material fix, we will offer what we can — usually credit, always the credit line.

Ask us something specific.

If a commitment on this page is not detailed enough for a procurement review or a story, write to us and we will answer with the actual figure.