Security. What is built, and what is not there yet.
This page says what the platform does to protect your apps and your data, and what it does not do yet. It lists only what is built.
In short
Each replica of an app runs in its own virtual machine, and each team has its own private network.
Environment variables are stored encrypted. Only the owner and the admins of a team can see their values.
You sign in with a code sent to your email. There are no passwords to steal.
Card details go to the payment provider and never reach our servers.
There is no certification, no audit report and no service level agreement yet. What is not there yet
Found a vulnerability? Write to security@arrangic.com.
How apps are kept apart
- Each replica of your app runs in its own virtual machine. It does not share one with the apps of other customers.
- The apps of a team are on a private network of their own. The apps of other teams cannot reach it.
- Every app is built in its own build environment, with its own cache. A build cannot read the code or the cache of another app.
- From the internet, an app can be reached on ports 80 and 443 only.
HTTPS
Every app is served over HTTPS, at its platform address and at your own domains. A request over plain HTTP is redirected. The certificates are issued and renewed automatically. The dashboard is served over HTTPS as well.
Environment variables
- Variables are stored encrypted (AES-256).
- Their values are shown only to the owner and the admins of the team. A member can set a variable and cannot read existing values back.
- Every time someone reveals a value, the activity trail records it.
More in the documentation: Environment variables.
Signing in
- You sign in with a six-digit code sent to your email address. A code works for ten minutes and for five tries.
- How often a code can be requested is limited, for each email address and for each network address.
- There are no passwords, so there is none to leak and none to reuse.
- A browser stays signed in until you sign out, for 400 days at most. Sign out on a computer you share.
Your mailbox is the key to your account. Whoever can read it can sign in. Protect it with a second sign-in step at your email provider.
Teams and roles
Each person has an account of their own and joins a team as owner, admin or member. Members deploy and run apps; they cannot read the values of variables and cannot delete an app. Only the owner changes the plan and the payment method. The activity trail lists deployments and changes with who made them.
More in the documentation: Teams.
The GitHub connection
- You choose which repositories the connection can see.
- We read from them: the code to build, and the commit a deployment came from. We do not write to them.
- Access to GitHub uses tokens that are created when they are needed and expire within an hour.
- When GitHub tells us about a push, the notice is checked by its signature before anything is done with it.
Payments
Card details are entered at the checkout of our payment provider and never reach our servers. We keep the brand of the card, its last four digits and its expiry date, so that the billing settings can show which card is used.
Who of us can see your data
A small number of authorized staff can see accounts, teams, apps and billing records. To give support, or to look into a fault or abuse, they can sign in to a customer's account through a link that works for two minutes. Creating such a link and using it are recorded, with who did it and from where. They do this for those reasons only.
No tracking
This website and the dashboard use no analytics, no session recording and no advertising. The cookie policy lists the few cookies the dashboard needs, and the privacy policy says what data we hold.
What is not there yet
When one of these changes, this page will say so.
- No certification and no independent audit. There is no SOC 2 report and no ISO 27001 certificate.
- No service level agreement. No uptime is promised.
- No second sign-in step in the dashboard, and no single sign-on.
- No backups of what your app writes. The disk of an app is temporary: it is lost at every deployment, at every restart and when the app sleeps.
- No paid rewards for vulnerability reports.
Your part
- Keep your code and its dependencies up to date.
- Put secrets in environment variables, not in the repository.
- Do not print secrets or personal data to the log. Nothing is filtered out of it, and every member of your team can read it.
- Keep your data in a database or a store outside the app, and back it up.
- Give each person the lowest role that works, and remove people who leave.
- Protect the mailbox you sign in with.
Report a vulnerability
Write to security@arrangic.com. Say what you found, where, and how to reproduce it. The same address is in security.txt.
security@arrangic.comWhat we ask of you
- Test only with your own account and your own apps.
- Do not read, change or delete the data of other customers. If you come across it, stop and tell us.
- No denial of service, no spam, and no attempts to trick our staff.
- Give us 90 days to fix the problem before you publish it.
What you can expect from us
- An answer within 2 working days.
- Word on what we found, and again when it is fixed.
- No legal action against research done in good faith and within these rules.
Draft. The address for reports and the times named on this page are placeholders until launch.