Security
This page describes what happens to the HTML you send and what oJo keeps. oJo is run by one person and holds no certification of its own.
How a render is isolated
- One browser per job. Every job renders in its own sandboxed browser, which is closed when the job ends. No two jobs, and no two customers, share a browser.
- The page has no network of its own. Its images, fonts, stylesheets and scripts load only from
public
https://addresses ordata:URLs, fetched by oJo on the page’s behalf. - Private addresses are refused. Nothing in your HTML can reach an internal or private address.
What your HTML can load, and the size and time limits, are under Resource Limits.
What oJo keeps
- Your renders. Each image or PDF is stored with the HTML and variables that produced it, so you can list and fetch it again through the API.
- Deleting a render removes the stored file. Its record, including the HTML and variables, is marked deleted and kept.
- Payments are handled by Paddle , the merchant of record. Card details never reach oJo.
Providers
oJo runs on providers that hold security certifications. Their certifications cover them, not oJo.
| What | Provider | Their certification |
|---|---|---|
| Servers, in Germany | Hetzner Online GmbH | ISO/IEC 27001:2022 for all its hosting services and data centres, and a BSI C5:2020 Type 2 attestation covering its cloud servers |
| DNS and network, and stored files in a European R2 bucket | Cloudflare | ISO/IEC 27001, 27701 and 27018, SOC 2 Type II (list ) |
| Database and sign-in, in a European project | Supabase | SOC 2 Type 2 and ISO/IEC 27001 (security ) |
| Payments | Paddle | Merchant of record. Card details go to Paddle and never reach oJo |
Availability
Uptime of the API and the website is measured from outside and published at status.ojo.so .
Reporting a vulnerability
Email [email protected]. You will get a reply from the person who runs oJo.