Security

Clear boundaries.
Practical controls.

Security is part of how you configure, connect, and operate your services. Here are the controls available in Helicarrier Cloud and the responsibilities that stay with your application.

Platform controls

Access you can reason about.

Scoped automation

Create account, project, or service API keys. Project and service keys use an explicit permission allowlist, with environment restrictions available for project keys.

Private service connectivity

Connect applications and databases within a project. New managed databases default to private access; public exposure is a separate setting.

HTTPS for public apps

Automatic certificates protect public HTTP services once domains are configured and DNS verification succeeds.

Secret handling

API keys are stored as hashes and shown once. Environment values and managed database credentials are encrypted in platform storage.

Project membership

Invite teammates to the projects they need. Automation keys remain bounded by the access of the user who created them.

Runtime options

Application containers use platform hardening controls. Supported services can opt into a read-only root filesystem on their next deployment.

Shared responsibility

Your application is still yours.

Keep application dependencies patched, validate user input, and choose safe access settings. The platform provides controls; your workload and configuration determine how they are used.

  • Keep independent copies of data you cannot lose
  • Restrict public database access with IP allowlists and supported TLS
  • Store keys outside your repository and revoke unused credentials

Report a vulnerability.

Send a description and steps to reproduce to our security contact. Avoid posting credentials, personal data, or exploitation details in a public issue.

[email protected]

For account or deployment assistance, contact open a support request.