PreviewRustaBase OSS is in public preview. Build on managed PostgreSQL with APIs, authentication, storage, realtime, and server-side functions.Read the product direction

Security

Security

RustaBase protects your Projects in layers: the network, the platform, each Project, and your data. This page covers what we do for you, and what you should do yourself.

What RustaBase does

LayerProtection
NetworkVisitors reach Projects only through our load balancer over HTTPS. Servers talk to each other over a private network
AddressesYour Project uses its public rustabase.net address. Server addresses are never shown in the console or API
IsolationEach Project has its own database credentials. Free and paid Projects run on separate servers
RuntimeProject backends run without admin rights, with resource limits
Sign-inPasswords are hashed, sessions are signed, and two-step sign-in is available
SecretsCredentials are encrypted at rest and never shown again after saving

What you control

ControlWhere
Table access rulesTables, for each of list, view, create, update, delete
Row-level securityRow-level security, as PostgreSQL policies
API keysAPI keys, scoped and revocable
Webhook signingWebhooks, Security & retries
Team accessWorkspace members and Audit

Before you go live

  1. Check the access rules on every table. Leave nothing open that shouldn't be.
  2. Turn on two-step sign-in for every workspace member.
  3. Keep API keys and superuser access on servers only, never in apps.
  4. Set a signing secret on every webhook.
  5. Turn on automatic backups and practice a restore.
  6. Review Security in the console and fix any findings.

If a key or password leaks

  1. Revoke the key, or change the password, straight away.
  2. Create a new one and update the service that uses it.
  3. Check Logs and Audit for anything unusual since it leaked.
  4. Remove it from the place it leaked, such as a repository or chat.

Report a vulnerability

Email [email protected] privately. Please don't post details publicly until we've fixed the issue.

Acknowledgments

Found something wrong on this page?

Fix it yourself. The link below opens this file in GitHub's editor and forks the repository for you if you need one, and your change becomes a pull request without leaving the browser.