Security
Clear boundaries.
Practical controls.
Security is part of how you configure, connect, and operate your services. Here are the controls available in Helicarrier Cloud and the responsibilities that stay with your application.
Platform controls
Access you can reason about.
Scoped automation
Create account, project, or service API keys. Project and service keys use an explicit permission allowlist, with environment restrictions available for project keys.
Private service connectivity
Connect applications and databases within a project. New managed databases default to private access; public exposure is a separate setting.
HTTPS for public apps
Automatic certificates protect public HTTP services once domains are configured and DNS verification succeeds.
Secret handling
API keys are stored as hashes and shown once. Environment values and managed database credentials are encrypted in platform storage.
Project membership
Invite teammates to the projects they need. Automation keys remain bounded by the access of the user who created them.
Runtime options
Application containers use platform hardening controls. Supported services can opt into a read-only root filesystem on their next deployment.
Shared responsibility
Your application is still yours.
Keep application dependencies patched, validate user input, and choose safe access settings. The platform provides controls; your workload and configuration determine how they are used.
- Keep independent copies of data you cannot lose
- Restrict public database access with IP allowlists and supported TLS
- Store keys outside your repository and revoke unused credentials
Report a vulnerability.
Send a description and steps to reproduce to our security contact. Avoid posting credentials, personal data, or exploitation details in a public issue.
[email protected]For account or deployment assistance, contact open a support request.