Skip to content

Security. What is built, and what is not there yet.

This page says what the platform does to protect your apps and your data, and what it does not do yet. It lists only what is built.

In short

How apps are kept apart

  • Each replica of your app runs in its own virtual machine. It does not share one with the apps of other customers.
  • The apps of a team are on a private network of their own. The apps of other teams cannot reach it.
  • Every app is built in its own build environment, with its own cache. A build cannot read the code or the cache of another app.
  • From the internet, an app can be reached on ports 80 and 443 only.

HTTPS

Every app is served over HTTPS, at its platform address and at your own domains. A request over plain HTTP is redirected. The certificates are issued and renewed automatically. The dashboard is served over HTTPS as well.

Environment variables

  • Variables are stored encrypted (AES-256).
  • Their values are shown only to the owner and the admins of the team. A member can set a variable and cannot read existing values back.
  • Every time someone reveals a value, the activity trail records it.

More in the documentation: Environment variables.

Signing in

  • You sign in with a six-digit code sent to your email address. A code works for ten minutes and for five tries.
  • How often a code can be requested is limited, for each email address and for each network address.
  • There are no passwords, so there is none to leak and none to reuse.
  • A browser stays signed in until you sign out, for 400 days at most. Sign out on a computer you share.

Your mailbox is the key to your account. Whoever can read it can sign in. Protect it with a second sign-in step at your email provider.

Teams and roles

Each person has an account of their own and joins a team as owner, admin or member. Members deploy and run apps; they cannot read the values of variables and cannot delete an app. Only the owner changes the plan and the payment method. The activity trail lists deployments and changes with who made them.

More in the documentation: Teams.

The GitHub connection

  • You choose which repositories the connection can see.
  • We read from them: the code to build, and the commit a deployment came from. We do not write to them.
  • Access to GitHub uses tokens that are created when they are needed and expire within an hour.
  • When GitHub tells us about a push, the notice is checked by its signature before anything is done with it.

Payments

Card details are entered at the checkout of our payment provider and never reach our servers. We keep the brand of the card, its last four digits and its expiry date, so that the billing settings can show which card is used.

Who of us can see your data

A small number of authorized staff can see accounts, teams, apps and billing records. To give support, or to look into a fault or abuse, they can sign in to a customer's account through a link that works for two minutes. Creating such a link and using it are recorded, with who did it and from where. They do this for those reasons only.

No tracking

This website and the dashboard use no analytics, no session recording and no advertising. The cookie policy lists the few cookies the dashboard needs, and the privacy policy says what data we hold.

What is not there yet

When one of these changes, this page will say so.

  • No certification and no independent audit. There is no SOC 2 report and no ISO 27001 certificate.
  • No service level agreement. No uptime is promised.
  • No second sign-in step in the dashboard, and no single sign-on.
  • No backups of what your app writes. The disk of an app is temporary: it is lost at every deployment, at every restart and when the app sleeps.
  • No paid rewards for vulnerability reports.

Your part

Report a vulnerability

Write to security@arrangic.com. Say what you found, where, and how to reproduce it. The same address is in security.txt.

security@arrangic.com

What we ask of you

  • Test only with your own account and your own apps.
  • Do not read, change or delete the data of other customers. If you come across it, stop and tell us.
  • No denial of service, no spam, and no attempts to trick our staff.
  • Give us 90 days to fix the problem before you publish it.

What you can expect from us

  • An answer within 2 working days.
  • Word on what we found, and again when it is fixed.
  • No legal action against research done in good faith and within these rules.

Draft. The address for reports and the times named on this page are placeholders until launch.