Vulnerability management
Keeping the platform secure isn't a one-off act, but a continuous
process of updating and monitoring.
Patching and updates
- The software images that make up the platform are rebuilt and
updated regularly to incorporate security fixes.
- Updates are applied through the same declarative, versioned, and
reversible process as any other change (see
Deployments and changes), so
every update is logged and can be rolled back.
- Critical fixes are prioritized and applied on an accelerated basis.
Monitoring
- We follow the security advisories of the components we use.
- The platform is continuously monitored to detect anomalous behavior
(see Monitoring).
Reduced surface
The less that's exposed, the less there is to defend. By design, the
platform exposes the minimum to the Internet and segments the rest,
reducing the attack surface (see Network security).
Responsible disclosure
If you detect a possible security issue in the service, please report it
to us responsibly through the
support channels. We'll treat it with
priority and confidentiality.
Pending validation
If your evaluation requires information about specific security
assessments (for example, periodic penetration tests), let us know: we
can provide the available detail under the corresponding
confidentiality agreement.