Data isolation

Isolated by design: every organisation's data and experiments are kept strictly separate, so one can never reach another's.

Authentication & access

JWT and API-key authentication, role-based access control (Admin, Operator, Viewer) and license-driven feature gating on every request.

Data protection

Encryption in transit, secret material kept in your secret store, and RSA-signed license tokens verified against a public key you control.

Observability & audit

End-to-end OpenTelemetry tracing, structured logs, and an immutable audit trail of every governance decision — approvals, aborts and kill-switch events.

Safe-by-design chaos

Blast-radius limits, dry-run, an error-budget gate and a background safety monitor mean an experiment can never quietly become an outage.

Deployment control

Run in our managed SaaS, or deploy the Kubernetes Operator in your own cluster where data never leaves your perimeter.

Compliance & practices

  • SOC 2-aligned controls and processes, with formal certification on the roadmap.
  • GDPR-aligned data handling; data residency honoured in private-cloud deployments.
  • Least-privilege service accounts and scoped API keys with expiry and revocation.
  • Regular dependency scanning and a documented incident-response process.

Responsible disclosure

Found a vulnerability? We appreciate coordinated disclosure and will work with you on a fix and acknowledgement. Please email our security team before sharing details publicly.

security@faultmesh.com

Need our security package?

Request our security whitepaper, subprocessor list and questionnaire responses.

Contact us