Application Security
The Encore platform makes strong security the default path
Built on industry experience
The security practices in the Encore platform are built on our team's decades of experience designing and operating sensitive systems at companies like Google, Spotify, and Monzo.
Security by Default
The Encore platform is designed to make security effortless rather than burdensome:
- Zero-config security: Focus on building features while the Encore platform automatically implements security best practices
- Built-in secrets management: Safely handle sensitive data using the built-in secrets management system
- Automated IAM management: the Encore platform automatically manages IAM policies based on the principle of least privilege
Security features
When the Encore platform deploys your application and infrastructure, it takes care of implementing security best practices:
- Strong encryption: All communication uses mutual TLSv1.3
- Secure databases: Database access is encrypted with certificate validation and strong security credentials
- Isolated database credentials: Each database instance has unique credentials, and each container connecting to a database uses its own credential. Credentials can be rotated via the dashboard.
- Cloud security: Automatic provisioning with security best practices specific to each cloud provider
- Learn more about Google Cloud Platform (GCP)
- Learn more about Amazon Web Services (AWS)
- Infrastructure safety: Deletion protection, admin-only environment management, and full audit trails for infrastructure changes. Learn more in Managing Infrastructure.