Skip to content

Security that starts at the boundary your cloud already enforces.

SKE never hosts your workloads. It acts in your accounts through credentials you issue and can revoke at any time.

Data boundary

Your data stays in your cloud. SKE only orchestrates.

Resources are created in accounts your organization owns, in the regions you pick for each environment. Your existing controls, guardrails and compliance scope keep applying.

Your AWS account or GCP project

  • Functions and containers
  • Databases and caches
  • Queues and schedules
  • Networks and subnets
  • Secrets and certificates
  • Logs, metrics and the invoice

What SKE stores

  • Project and environment configuration
  • Deployment history
  • Roles and access policies
  • Audit events
  • Your cloud credentials, encrypted

Cloud access

You issue the credentials. You can revoke them in one step.

Amazon Web Services

You create an IAM role in your account that trusts SKE only when a unique external ID is presented. SKE receives short-lived credentials from AWS STS. No access keys are exchanged.

{
  "Effect": "Allow",
  "Principal": { "AWS": "arn:aws:iam::<ske-account>:root" },
  "Action": "sts:AssumeRole",
  "Condition": {
    "StringEquals": { "sts:ExternalId": "<your-external-id>" }
  }
}

To revoke access, delete the role or remove its trust statement.

Google Cloud Early access

You create a service account in your project and upload its key. SKE stores it encrypted and uses it to provision and operate your environments. Disable the key to cut access.

Least privilege, documented

The IAM reference lists every permission SKE uses and why, so your reviewers can approve it line by line.

Read the IAM reference

Controls your reviewers will ask about.

Identity and sessions

  • Passwordless sign-in with single-use links that expire after ten minutes.
  • Access tokens last fifteen minutes; refresh tokens rotate on every use.
  • Replaying an old refresh token revokes the whole session family.

Authorization

  • Roles on the organization, a workspace, a project or one environment.
  • Custom roles built from granular permissions.
  • API tokens are scoped, cannot exceed their creator and expire within a year.

Secrets and data

  • Application secrets live in SSM Parameter Store or Secret Manager in your account.
  • Cloud credentials held by SKE are encrypted at rest.
  • Databases and caches sit on private subnets, off the public internet.

Change safety

  • Protected environments require a dedicated permission and a confirmation.
  • Releases are immutable images, and rollback does not rebuild.
  • Every change is recorded in the audit log with before and after values.

Found a vulnerability?

Tell us privately through the contact form and the team will follow up. Please test only against resources you own.