Shipyard
Security
How we approach privacy, isolation, and safe publishing while you build with Shipyard.
Last updated August 8, 2026
Private until you publish
Drafts and previews stay under your account. A project is only public when you choose to publish it. You decide when a version is ready for the outside world.
Isolated project workspaces
Builds run in isolated environments so one project’s preview does not bleed into another. Generated apps are scoped to your workspace and the collaborators you invite.
Account protection
Access to Shipyard requires authentication. Keep your credentials private, sign out on shared devices, and use a unique password for your account.
Uploads and prompts
Files and prompts you attach are used to generate and refine your app. Avoid uploading production secrets, private keys, or unnecessary personal data. Prefer placeholders until you are ready to configure live credentials in a secure environment.
Published apps
When you publish, you are responsible for the content, forms, and data collection your app exposes. Lead forms and analytics should only collect what you need, and you should disclose that collection to your visitors when required.
Responsible disclosure
If you believe you found a security issue in Shipyard, email security@shipyard.app with enough detail for us to reproduce it. Please give us a reasonable window to investigate before public disclosure.