Every request lands on our edge first. Layer 3 and 4 floods are absorbed there and never reach an origin, and the mitigation stays on by default rather than being a setting somebody has to remember.
A current SOC 2 Type II report, our latest penetration test summary and a completed CAIQ questionnaire. All three go out under mutual NDA, usually the same working day.
We act as a processor under GDPR, publish standard contractual clauses and let you pin builds, logs and caches to European regions only.
ISO 27001 for the management system and ISO 27018 for cloud personal data, both recertified annually by an accredited external auditor.
Yes. The DPA is countersigned in the dashboard on any paid plan, and legal will red-line a bespoke version for organisations above 200 seats.
On the Scale plan we sign a business associate agreement and enable the isolated runtime, restricted logging and stricter retention defaults that HIPAA work needs.
The platform is assessed as a PCI DSS service provider for the hosting layer. Card data itself should stay with your payment processor rather than transiting your own functions.
Previews are private to the workspace unless you publish them. You can gate them behind SSO, a shared password or an allowlist of email domains, per project.
Yes — AES-256 at rest and TLS 1.3 in transit, with keys rotated on a 90 day cycle and held in a hardware-backed key service separate from the compute fleet.
Metadata is snapshotted every fifteen minutes and replicated across three zones. Restores are rehearsed quarterly; the last drill returned a full workspace in 11 minutes.
On dedicated capacity inside tier-three data centres across 26 metros, fronted by our own edge network. A current region and subprocessor list is on the trust page.
Each deployment runs in its own sandboxed runtime with a private network namespace. Nothing is shared between workspaces beyond the anycast layer that routes to them.
Twice a year against the full platform, plus a targeted test before any change to the auth or build pipeline. Findings are triaged within one business day.
A short, published list covering hosting, error reporting and billing. We give 30 days notice before adding one, and you can subscribe to that notice by email.
We do. Rewards run from $250 for a low-severity report to $18,000 for a confirmed remote execution finding, and researchers keep credit in the changelog.
Yes, with a managed ruleset that ships updates automatically and a rule editor for anything specific to your app. Rules can run in observe mode before you enforce them.
Managed rules map to each OWASP category, and the platform sets secure defaults for headers, cookies and CORS so the common misconfigurations never ship in the first place.
SAML single sign-on, SCIM provisioning, hardware key enforcement and role-based permissions down to a single project. Every session appears in an exportable audit log.
Immutable hosts, no interactive shell access in production, signed build artifacts and continuous configuration drift detection with alerting to an on-call rota.
Dependency scanning on every build, a locked egress allowlist, secrets held outside the bundle and automatic revocation of any token that appears in a public repository.
Ready to ship? Start a project on the free tier. Ask an engineer about Team or Scale.
Try Duskmoor Scale with faster builds, wider egress, longer log retention, and more.