Development preview · The platform is under development. Live cloud resources and paid services are not available yet.Documentation
UYGULAMA CLOUD

Security

Implemented boundaries matter more than a badge. These controls apply to the current control plane; live customer workload infrastructure is not available yet.

Accounts and sessions

Passwords use Argon2id hashes. Session and email-link tokens are stored as hashes. Password resets revoke existing sessions. Production session cookies use HttpOnly and Secure attributes.

Organization and record ownership

The API checks organization membership for projects, services and child resources. Knowing a resource ID does not grant access. Platform admin permission is separate from registration, and sensitive actions are audited.

Secret storage

Service environment values are encrypted with AES-256-GCM. Lists do not return secret values. Logging scope is limited to avoid recording passwords, tokens and environment secrets.

Assurances not yet offered

Customer workload isolation, automated backups, restore drills, independent monitoring and certification are not complete. Existing controls do not imply these are ready; they require separate validation before live providers open.