# Know how your app is protected

See how network isolation, scoped access, and managed TLS work. Understand what Watasu manages and what you control.

[Explore the controls](https://watasu.io/security#controls) [Contact security](mailto:security@watasu.io)

## Isolation, access and managed TLS

These controls govern how your app connects, who can manage it, and how public traffic reaches it.

[Read the technical docs](https://docs.watasu.io/)

### Team networks with explicit trust

Teams have isolated runtime networks. Private TCP services accept traffic only from explicitly trusted apps, even within the same team. Trust is directional. Your application still authenticates and authorizes callers.

[Private networking](https://docs.watasu.io/apps/private-networking/)

### Managed TLS for public endpoints

Managed application URLs use HTTPS. Custom, apex, and wildcard domains receive certificates that Watasu provisions and renews while the required DNS configuration remains in place.

[Domains & certificates](https://docs.watasu.io/apps/custom-domains/)

### Roles for apps and pipelines

App and pipeline roles separate viewing, deployment, operation, and management. Pipeline permissions extend to review apps. Locked apps require an explicit access grant, and team membership alone does not grant access to every existing app.

[Teams & access](https://docs.watasu.io/admin/teams-and-access/)

### Keep configuration out of source code

Application configuration is injected at runtime. Variables marked as secret have restricted visibility in the control plane. Attached services supply their connection variables, so your source code does not need embedded credentials.

[Configuration & secrets](https://docs.watasu.io/apps/configuration/)

## Replicas, failover and recovery

Set process replica counts and choose service plans with the replication and backup options your app needs.

### EU-hosted applications and data

App workloads run in Germany. Processes with two or more replicas are spread across eligible EU zones. Managed services provide different replication and availability options by plan.

[Placement & regions](https://docs.watasu.io/reference/regions/)

### Replication and failover by plan

PostgreSQL Premium adds a synchronous standby and automatic failover. Valkey Premium includes a managed HA standby. Replicated ClickHouse and Redpanda plans support production data workloads.

[Compare managed services](https://watasu.io/addons)

### Verify a restore before promotion

Supported PostgreSQL, Valkey, and ClickHouse plans provide backups. Restore creates a replacement that you can validate before promotion. The original remains until you choose to remove it.

[Backup & restore workflow](https://docs.watasu.io/workflows/backups-and-restores/)

Replication and backups serve different purposes. Availability, retention, and scheduled backups depend on the service and plan. See the [current plan catalog](https://docs.watasu.io/reference/addon-plans/) for plan details.

## Certifications and security reviews

Watasu does not currently hold SOC 2 or ISO 27001 certification. Externally audited penetration-test reports are not currently available.

Tell us which security requirements your team needs to meet. We’ll discuss the controls in place and the evidence we can provide.

[Discuss your requirements](mailto:security@watasu.io)

### Policies and service status

- [Privacy policy](https://watasu.io/privacy)
- [Data processing agreement](https://watasu.io/dpa)
- [Subprocessors](https://watasu.io/subprocessors)
- [Terms of service](https://watasu.io/terms)
- [Platform status](https://watasu.statuspage.me/)

### The security controls you manage

Watasu manages the platform’s network and access boundaries. You manage application authentication, permissions, dependencies, and data access. You also decide which services to expose. Private networking complements those controls.

## Found a vulnerability? Tell our security team

Send the affected resource, a description, and steps to reproduce. Leave credentials and customer data out of your report.

[Email security@watasu.io](mailto:security@watasu.io)
