Your code. Our infrastructure.Meet Openstead.
openstead

SECURITY AT OPENSTEAD

Clear boundaries.
Deliberate access.

The controls you need to manage who can change your services, how they connect, and where your application’s configuration lives.

PLATFORM CONTROLS

Built into the way
you operate.

Keep account access deliberate.

Protect your account with two-factor authentication. Use workspace roles to separate administration, development, and read-only access. Paid workspaces can require two-factor authentication for their members.

Keep internal connections private.

Connect applications to private services and managed databases through their private addresses. PostgreSQL and MySQL stay on the private network rather than exposing database ports to the public internet.

Put HTTPS on your domain.

Connect a custom domain, verify its DNS records, and let Openstead manage the HTTPS certificate. Review domain status from the service that owns it.

Keep configuration out of your repository.

Manage environment variables and secrets in the console. Stored secret values are encrypted by the platform and supplied to the services that use them.

Make recovery part of your routine.

Managed PostgreSQL and MySQL services include backup and restore controls. Review successful backups and test restoration against your application’s recovery needs.

Know what changed.

Deployment history connects releases to their source. Workspace activity records give your team a place to review changes, and paid workspaces can export audit records.

SHARED RESPONSIBILITY

A clear view of
who handles what.

01

Openstead operates the platform.

We provision hosting resources and operate the service deployment and routing systems.

  • Manage platform infrastructure and runtime capacity.
  • Apply workspace permissions and service configuration.
  • Manage certificates for verified service domains.
  • Provide database backup and restoration tools.
02

You protect your application.

You control your code, its users, and the data your application processes.

  • Secure account, repository, and team access.
  • Keep dependencies and application authentication current.
  • Review secrets, permissions, and public endpoints.
  • Test migrations, backups, and your recovery process.

REPORT AN ISSUE

Something needs
our attention?

Use the contact form to share the affected service or page, a description, and reproduction steps. Please leave passwords, private keys, and customer data out of the report.

Contact the team Manage your account