Security and policy
Kuberns deploys and operates workloads on AWS-backed infrastructure. Backend integrations include IAM, EC2, ECR, SSM, Secrets Manager, CodeBuild, CodeDeploy, CodePipeline, CloudWatch, and SES.
Platform controls verified in source
- OAuth and OTP authentication paths.
- Role-based service permissions.
- GitHub webhook HMAC signature verification.
- IAM-based AWS orchestration.
- Encrypted storage for payment autopay tokens.
- Temporary agent infrastructure cleanup.
- Service health checks and recorded healing events.
These implementation details are not a certification or a guarantee that every workload meets a particular regulatory standard.
Shared responsibility
Kuberns operates supported infrastructure workflows. You remain responsible for:
- Application code and dependencies.
- Secrets and external credentials you provide.
- User access decisions.
- Data classification, retention, and backups.
- Secure application configuration.
- Compliance requirements for your workload.
- Reviewing destructive resource operations.
Public policies
Read Security practices before deploying production data.