Compliance

Audited by independent firms

Reports and certificates are available to customers under NDA. Ask your account team or request them from the security team.

  • Certified

    SOC 2 Type II

    Annual audit of security, availability, and confidentiality controls.

    Report under NDA

  • Certified

    ISO/IEC 27001

    Certified information security management system, audited every year.

    Certificate on request

  • Compliant

    GDPR

    Data processing agreement, EU data residency, and subprocessor notices.

    DPA available

  • In progress

    HIPAA

    Business associate agreements for workloads that handle health data.

    Target: Q2 2027

Secure by default, on every plan

Encryption, isolation, and access controls are on from the start, so security reviews begin from a strong baseline.

  • Private networking

    Services talk over a private network, with no VPC to configure.

  • DDoS protection

    Network-level protection on every service, with nothing to set up.

  • Compliance controls

    Data residency, retention settings, and access reviews that support your audits.

  • Audit logs

    A searchable record of every change to services, members, and keys.

  • Encryption at rest

    Databases, backups, and secrets are encrypted by default.

  • Role-based access

    Control who can view and change each service and resource.

Practices

How we keep your data safe

The controls behind the platform, grouped the way security questionnaires ask about them.

Ask the security team

Infrastructure

01Where does the platform run?

In tier-3 data centers operated by major cloud providers, across separate availability zones in every region. Physical access is limited to the providers' audited staff.

02How are customer services isolated?

Each service runs in its own sandboxed instance with a dedicated filesystem. Workspaces are separated at the network level, and private networking never crosses workspace boundaries.

03How do you handle patching?

Base images and hosts are rebuilt weekly and patched within 72 hours for critical vulnerabilities. Rollouts use the same zero-downtime deploys as your services.

Data

04Is my data encrypted?

Yes. Data is encrypted in transit with TLS 1.2 or later and at rest with AES-256. Encryption keys are rotated automatically and stored in a managed key service.

05Where is my data stored?

In the region you choose for each service and database. Backups are encrypted and stay in the same region, so EU workspaces can keep all data in the EU.

06What happens to my data when I delete a service?

Volumes and databases are deleted right away. Backups expire within 30 days, after which the data cannot be recovered.

Access

07Who at the company can access my data?

Only on-call engineers, through just-in-time access that you can require approval for. Every session is logged, time-limited, and reviewed.

08Do you support single sign-on?

Yes. Team and Enterprise plans support SAML single sign-on, enforced two-factor authentication, and SCIM provisioning for members and roles.

09How are API keys and secrets protected?

API keys can be scoped to a workspace, project, or service and set to expire. Environment variables marked as secrets are encrypted and never shown in logs.

Monitoring

10How do you detect incidents?

Infrastructure and audit events stream into a central detection pipeline with alerts reviewed around the clock by the on-call security rotation.

11Will you tell me about a security incident?

Yes. Affected customers are notified without undue delay, and within 72 hours for incidents involving personal data, with a public post-incident report.

12Do you run penetration tests?

An independent firm tests the platform every year, and after major changes. Summaries of the latest report are available to customers under NDA.

Responsible disclosure

Found a vulnerability? Tell us first

We welcome reports from security researchers. Send the details privately and give us a reasonable window to fix the issue before you share it.

  • Reply within 1 business day
  • Safe harbor for good-faith research
  • Credit in our hall of fame

Free tier · No credit card

Push code today. Be live before your coffee cools.

Connect a repository, pick a region, and get a production URL with HTTPS, logs, and autoscaling already switched on.

$ git push origin main

  1. Build34 s
  2. Deploy12 s
  3. Health checks3 s

your-app.example.com

Buy NowTheme Details