Security

Last updated: September 7, 2026

What Ruby Native holds on your behalf, what it does with it, and how to take it back. Written for whoever reviews vendors on your team. If your review needs a questionnaire filled in, email joe@rubynative.com.

What we store

  • App Store Connect. Your Team ID, API key ID, issuer ID, and the .p8 private key. All four are encrypted at rest with Rails encrypted attributes, so the database and its backups never hold them in plain text.
  • Google Play. Nothing of yours. You invite our service account into your Play Console with Release manager access on the apps you choose. We never see your Google credentials, and the account can't reach apps you haven't invited it to.
  • Android upload key. We generate an upload keystore for your app and store it encrypted, so every build is signed consistently. Google Play App Signing holds the key that signs what users actually install.
  • Screenshot key. If you use automated screenshots, a per-app secret your Rails app recognizes so the capture can sign in. Encrypted like the rest.
  • Account data. Your email, app names and URLs, icons, config values, build history, and the launch pings described below. Stripe handles billing; we never see card numbers.

What we do with your App Store Connect key

Every call falls into one of five buckets: sign and build with Apple's cloud-managed certificate, register your bundle ID and the capabilities your config asks for, upload to TestFlight and manage a "Ruby Native" internal test group, register a webhook so the dashboard knows when builds process and versions change state, and the optional screenshot and subscription-product calls if you use those features. Ruby Native never creates apps or changes settings it didn't create. The full list is in the credentials guide.

Why the key needs the Admin role. Apple ties cloud signing and bundle ID registration to Admin, offers no way to grant either to an App Manager or Developer key, and doesn't let Team Keys be limited to a single app. A lesser role could upload builds but couldn't sign them. You can revoke the key at any time in Users and Access; every future build fails immediately and nothing already on TestFlight or in a store is affected.

Where builds run

Builds run on GitHub-hosted runners, macOS for iOS and Ubuntu for Android, on a fresh virtual machine that is destroyed when the build ends. Your credentials are handed to that runner for the duration of the build and masked in its logs. The signed build goes from the runner straight to App Store Connect or Google Play and never passes through our server.

The build never checks out your Rails app. It points the native shell at your public web URL, the same way a browser would. We never need your source code or a login.

What your app sends us

Each launch sends a small ping with the bundle ID, the platform, and a random identifier generated once per install. No user ID, no email, and nothing from your Rails session. The request times out after five seconds and a failure is ignored, so your app never waits on us. Set analytics: false in config/ruby_native.yml to turn it off. If the app can't load its config, it reports the error type so the dashboard can show you.

That is the only traffic to rubynative.com. Your app loads its config and every page from your Rails app, and push tokens are posted to your Rails app, not to us.

Where the platform runs

rubynative.com runs on a server hosted by Hetzner in Hillsboro, Oregon. Database backups go to a private Amazon S3 bucket in the United States that the application can write to but not read back. Ruby Native is built and operated by Joe Masilotti, and production access is limited to him. No third party has standing access to your credentials.

Ruby Native has not completed a SOC 2 audit. If your review needs one, say so and we'll talk about what would satisfy it.

Subprocessors

  • GitHub runs the build pipeline.
  • Hetzner hosts the platform.
  • Amazon Web Services stores uploaded files, screenshots, and backups.
  • Stripe handles billing.
  • Postmark sends transactional email.
  • Honeybadger collects error reports. Reports include app and account identifiers and the account email, never credentials.
  • Fathom provides cookieless analytics for the marketing site.
  • Cloudflare carries the ruby_native preview tunnel between your machine and your phone during development. That traffic never touches our servers.

Taking it back

  • Revoke the API key in App Store Connect under Users and Access, Integrations. Builds stop immediately. Your apps stay live.
  • Remove our service account from your Play Console under Users and permissions.
  • Archive the app from your dashboard to stop builds and emails. To have stored credentials and data deleted, email joe@rubynative.com.
  • The native source you've downloaded is yours to keep under the software license. It's a real Xcode and Android Studio project you can build and ship without us.

Reporting a vulnerability

Email joe@rubynative.com with what you found and how to reproduce it. Please don't test against other customers' apps or accounts.