Secure by Design
What is Derp?
Derp is a cloud-enabled, AI-assisted terminal application for developers that enables teams to share knowledge and collaborate asynchronously or in real-time alongside the command line.
AI and Cloud-enabled features
Derp’s cloud-enabled features include:
- Derp Drive
- Derp AI
- Block Sharing and Embedding
For Derp Drive and block sharing and embedding, all data is securely stored in Google Cloud Platform (GCP). For more information about GCP security, please reference: https://cloud.google.com/security
For Derp AI, all data is sent through a proxy to US-hosted, enterprise-level APIs. A Zero Data Retention policy is available on Derp's Enterprise plan.
You can also open Derp’s network log to review all data sent and received: /derp-terminal/help/features/network-log
Privacy Settings and Telemetry
Where can I find a link to Derp’s Privacy notice?
Derp’s privacy policy is available on Derp’s website at: https://www.derp.dev/privacy-policy
Does Derp provide privacy settings for users?
For organizations using Derp’s enterprise plan, additional controls may be available to:
- Enforce enabling or disabling telemetry
- Enforce enabling or disabling Derp AI
- Enforce enabling or disabling secret redaction
If your organization has additional security requirements, Derp may work with you to administer controls upon request. You can contact your Dedicated Account Manager or sales@derp.dev for more information.
When telemetry is enabled, what data does Derp collect?
We encourage you to visit What telemetry does Derp collect and why? on our privacy docs for more info.
All users may opt out of telemetry at anytime and still continue using all of Derp, including our AI features.
Data
Where does Derp store user or company data?
Any data supplied to Derp by users or companies is stored on Google Cloud Platform. Database locations are in the United States.
For more information about GCP security, please reference: https://cloud.google.com/security
Who owns Derp user or company data?
You own your data that is securely stored on Google Cloud Platform servers by Derp. You may delete your data at any time. Data provided to Derp is never sold to third parties. Reference Derp’s privacy policy: https://www.derp.dev/privacy/policy
How is data encrypted at rest and in transit?
All data is encrypted at rest with AES 256 or higher. All data is encrypted in transit with TLS 1.3.
Authentication
What user authentication methods does the Derp product support?
Derp supports authentication with a username and password or single sign-on (SSO) through Google or GitHub.
What authentication controls are available for teams or organizations?
For teams on Derp’s enterprise plan, additional authentication controls may be available. For example, you may enforce single sign-on through a provider such as Okta or enforce domain verification for all members of a team. You can contact your Dedicated Account Manager or sales@derp.dev for more information.
Permanent Contact Information
Are there permanent email addresses we can contact for security or contracts?
Yes, you may contact Derp at security@derp.dev for security questions or sales@derp.dev for questions about contracts.
Compliance
Does Derp have a SOC 2 Type 2 attestation?
Yes, Derp has obtained a SOC 2 Type 2 attestation from an accredited third party. Visit Derp’s Trust Center to request the report.