Security is structural, not bolted on
FaultMesh deliberately breaks systems for a living — so it is built with isolation, least privilege and auditability at its core.
Data isolation
Isolated by design: every organisation's data and experiments are kept strictly separate, so one can never reach another's.
Authentication & access
JWT and API-key authentication, role-based access control (Admin, Operator, Viewer) and license-driven feature gating on every request.
Data protection
Encryption in transit, secret material kept in your secret store, and RSA-signed license tokens verified against a public key you control.
Observability & audit
End-to-end OpenTelemetry tracing, structured logs, and an immutable audit trail of every governance decision — approvals, aborts and kill-switch events.
Safe-by-design chaos
Blast-radius limits, dry-run, an error-budget gate and a background safety monitor mean an experiment can never quietly become an outage.
Deployment control
Run in our managed SaaS, or deploy the Kubernetes Operator in your own cluster where data never leaves your perimeter.
Compliance & practices
- SOC 2-aligned controls and processes, with formal certification on the roadmap.
- GDPR-aligned data handling; data residency honoured in private-cloud deployments.
- Least-privilege service accounts and scoped API keys with expiry and revocation.
- Regular dependency scanning and a documented incident-response process.
Responsible disclosure
Found a vulnerability? We appreciate coordinated disclosure and will work with you on a fix and acknowledgement. Please email our security team before sharing details publicly.
Need our security package?
Request our security whitepaper, subprocessor list and questionnaire responses.
Contact us