In scope
shardlyhq.xyz, the platform’s control plane and API, and the infrastructure that serves customer workloads.

Energy, hardware lifecycle, data protection, security disclosure and governance — written plainly, with no certification logos standing in for the actual commitment.
Workloads, backups and logs never leave the European Union.
Contracted at every facility; the mix is published, not offset.
Security reports are acknowledged within one day, always.
Nobody's return depends on a decision that is bad for customers.
A commitment that cannot be checked is a slogan. Each of these has a practice attached that somebody outside the company could verify.
Our facilities run on contracts for renewable supply, and we publish the mix rather than a carbon-neutral badge bought from a broker. Capacity is planned so machines run loaded instead of idling in reserve.
Owning the hardware means we also own what happens to it. Nodes are run to end of useful life, then wiped to a documented standard and resold or recycled — never landfilled and never sold with data on them.
Workloads, backups and logs stay inside the European Union. We collect the minimum needed to run and bill the service, and we will tell you exactly what that is if you ask.
Founder-owned with no outside shareholders. There is no board to satisfy and nobody whose return depends on a decision that would be bad for customers.
If you find a vulnerability in Shardly’s systems, write to hello@shardlyhq.xyz with “Security” in the subject line. You will get a human acknowledgement within 24 hours and a substantive reply within five working days.
Our side of the deal. We will not pursue legal action against anyone acting in good faith under this policy, we will keep you updated while we fix the issue, and we will credit you publicly unless you would rather we did not.
Your side. Give us reasonable time before publishing, do not access or modify data belonging to other customers, and do not run tests that degrade the service for anyone else.
shardlyhq.xyz, the platform’s control plane and API, and the infrastructure that serves customer workloads.
Findings in customer-uploaded code, social engineering of staff, physical access attempts, and volumetric denial of service. Report those as ordinary tickets instead.
We do not run a paid bounty yet and we would rather say so than imply one. Where a report leads to a material fix, we will offer what we can — usually credit, always the credit line.
If a commitment on this page is not detailed enough for a procurement review or a story, write to us and we will answer with the actual figure.