Security
Understand the boundary. Keep control of your cloud.
A starting point for reviewing Kapten’s deployment model, access requirements and operating responsibilities during early access.
Infrastructure ownership
Kapten is designed around infrastructure in the customer’s account. Your team controls that account and selects the deployment location. The application resources and their lifecycle should be visible to the people responsible for your cloud environment.
Explore the BYOC model to understand the relationship between the Kapten control plane and your application infrastructure.
Access and credentials
A platform that operates infrastructure needs permissions to do so. Review the connection method and the exact permissions for your onboarding setup before granting access. Assign an owner who can review and revoke that access.
The platform design includes protected handling of cluster credentials and a scoped-role model for cloud access. The connection method depends on the supported integration; confirm it for your deployment rather than assuming all providers work the same way.
Data and operational context
Application data stores run as part of your deployment. Platform management also involves operational information such as resource identifiers, deployment status and logs. Include those flows in your review, alongside application data and secrets.
Confirm the handling, location and retention of operational data for the capabilities you enable. Infrastructure location alone does not describe every data flow.
Shared responsibilities
Your team owns the application, its data and the cloud account. During onboarding, agree responsibility for access, updates, monitoring, backups, restore testing and incident response.
If you stop using Kapten, plan the transfer of operating responsibilities before disconnecting it. Keeping ownership of the infrastructure also means knowing who will maintain it.
Security review
Kapten does not currently offer a SOC 2 report or an ISO 27001 certification. The platform’s security design is not a substitute for a completed audit or your own deployment review.
If your organisation needs a particular report, contractual document or control, include that requirement in your early-access request so the team can confirm the current position.
Build with Kapten
Start with one service.
Build from there.
Tell us what you want to deploy. We review each request and follow up about fit and onboarding on your preferred cloud.
Free during early access. No card required. Cloud usage billed separately.