Security
Secure by default, not by configuration.
Isolation, secrets, and access come out of the project model rather than being assembled after the infrastructure is already running.
- 01Isolated workloadsEvery workload runs in its own application runtime. Project boundaries separate tenants at the platform level, so one application cannot reach the memory or filesystem of another.
- 02Encrypted by defaultData is encrypted in transit and at rest, and networking sits above individual resources so access is scoped through the platform.
- 03Secrets managementConfiguration and secrets are project resources, scoped to an environment and accessed through roles rather than scattered across services.
- 04Roles and permissionsOrganization and project roles govern who can deploy, read secrets, and manage resources, per resource and per environment.
- 05Audit trailDeployments, configuration changes, and access decisions stay reviewable in one place.
- 06Governance in the modelControls are expressed through the same platform layer that manages resources, instead of a second set of tools bolted on later.