Security & trust

Know how your
app is protected

See how network isolation, scoped access, and managed TLS work. Understand what Watasu manages and what you control.

Isolation, access
and managed TLS

These controls govern how your app connects, who can manage it, and how public traffic reaches it.

Read the technical docs

Team networks with explicit trust

Teams have isolated runtime networks. Private TCP services accept traffic only from explicitly trusted apps, even within the same team. Trust is directional. Your application still authenticates and authorizes callers.

Private networking

Managed TLS for public endpoints

Managed application URLs use HTTPS. Custom, apex, and wildcard domains receive certificates that Watasu provisions and renews while the required DNS configuration remains in place.

Domains & certificates

Roles for apps and pipelines

App and pipeline roles separate viewing, deployment, operation, and management. Pipeline permissions extend to review apps. Locked apps require an explicit access grant, and team membership alone does not grant access to every existing app.

Teams & access

Keep configuration out of source code

Application configuration is injected at runtime. Variables marked as secret have restricted visibility in the control plane. Attached services supply their connection variables, so your source code does not need embedded credentials.

Configuration & secrets

Replicas, failover
and recovery

Set process replica counts and choose service plans with the replication and backup options your app needs.

EU-hosted applications and data

App workloads run in Germany. Processes with two or more replicas are spread across eligible EU zones. Managed services provide different replication and availability options by plan.

Placement & regions

Replication and failover by plan

PostgreSQL Premium adds a synchronous standby and automatic failover. Valkey Premium includes a managed HA standby. Replicated ClickHouse and Redpanda plans support production data workloads.

Compare managed services

Verify a restore before promotion

Supported PostgreSQL, Valkey, and ClickHouse plans provide backups. Restore creates a replacement that you can validate before promotion. The original remains until you choose to remove it.

Backup & restore workflow

Replication and backups serve different purposes. Availability, retention, and scheduled backups depend on the service and plan. See the current plan catalog for plan details.

Certifications
and security reviews

Watasu does not currently hold SOC 2 or ISO 27001 certification. Externally audited penetration-test reports are not currently available.

Tell us which security requirements your team needs to meet. We’ll discuss the controls in place and the evidence we can provide.

Discuss your requirements

The security controls you manage

Watasu manages the platform’s network and access boundaries. You manage application authentication, permissions, dependencies, and data access. You also decide which services to expose. Private networking complements those controls.

Responsible disclosure

Found a vulnerability?
Tell our security team

Send the affected resource, a description, and steps to reproduce. Leave credentials and customer data out of your report.

Email security@watasu.io