rembrembdocs

Illustration by Annie Ruygt of a dark magic book with headline Fly Security

Report an issue: If you have a security concern, or believe you’ve found a vulnerability in any part of our infrastructure, please contact us. You can reach us at security@fly.io, and we can provide you with a Signal number if needed to convey sensitive information.

Corporate Security (“CorpSec”)

CorpSec is the practice of making sure Fly.io team members have secure access to Fly.io company infrastructure, and that secured channels are the only exposed channels to Fly.io. CorpSec controls are the primary concern of standards like SOC2.

Process Controls: Network/Infrastructure Security (“InfraSec”)

InfraSec is the practice of ensuring a hardened, minimal attack surface for components we deploy on our network. Conventionally, modern InfraSec centers on “cloud security”; of course, we are ourselves a cloud provider, which makes the job more interesting.

Application Security (“AppSec”)

AppSec is the practice of ensuring software is secure by design, secured during development, secured with testing and review, and securely deployed.

Vulnerability Remediation

Vulnerabilities that directly affect Fly.io’s systems and services will be patched or otherwise remediated within a timeframe appropriate for the severity of the vulnerability, subject to the public availability of a patch or other remediation instructions.

Severity: Timeframe

If there’s a severity rating that accompanies a vulnerability disclosure, we’ll generally rely on that as a starting point, but may upgrade or downgrade the severity in our best judgement.

SOC2 and HIPAA

We have our SOC2 Type 2 where we’ve documented a bunch of these controls. Additionally, we’ve detailed a number of controls for folks exploring running HIPAA-compliant applications on our platform.

Questions?

Email us!