Security & compliance

Enterprise-grade security, governed by construction.

Kubentic never stashes your cloud credentials. Every move is logged, every session is audited, no fuss, no muss.

how we protect you

Security baked into every layer.

Short-lived credential tokens

Kubentic talks to your cloud with scoped, time-limited tokens, nothing more. Zero secrets parked on our servers. Set it and forget it.

JWT-authenticated terminal

Every WebSocket terminal session gets a signed token with a configurable expiry. Go idle and it shuts itself down, no loose ends.

Role-Based Access Control

Dial in permissions per cluster, per namespace, per team, governance built in. Roles: Viewer, Operator, Admin, Owner.

Full audit log

Every move, who shipped what, who opened a terminal, who changed a permission, lands with a timestamp and an identity. Export it as CSV or JSON any time.

SOC 2 Type II ready

Architected from the ground up to meet SOC 2 controls for availability, security, and confidentiality.

TLS everywhere

Every byte between your browser, Kubentic, and your infrastructure is encrypted in transit. No exceptions.

Governance

Governance, built in, down to the namespace.

Dial in granular permissions per cluster, per namespace, per team. Four built-in roles cover every access pattern, batteries included:

ViewerOperatorAdminOwner

Every ship, terminal session, and permission change is logged with a timestamp and an identity, exportable as CSV or JSON.

Compliance

Built to clear the bar auditors set.

SOC 2 Type II

Ready

Architected from day one to meet SOC 2 controls for availability, security, and confidentiality.

TLS 1.2+

Every byte encrypted in transit, end to end.

Scoped credentials

Short-lived, least-privilege tokens. Nothing stored, ever.

Full audit trail

Every move attributable, exportable, retained.

security faq

Your security questions, answered.

Is my cloud provider data stored by Kubentic?

Nope. Kubentic talks to your cloud provider APIs with short-lived, scoped credential tokens, that's it. No long-term credentials ever land on Kubentic servers.

How are terminal sessions secured?

Every in-browser terminal session runs over a TLS-encrypted WebSocket, locked down with a signed JWT that carries a configurable expiry. Go idle and the session shuts itself down, secure by construction.

Can I export our audit log for compliance review?

You bet. The full audit log, who shipped what, who opened a terminal, who changed a permission, is exportable as CSV or JSON any time you need it.

Security that ships
at warp speed.

Audited end to end. Just a cloud account and a browser, and you're in.

Free plan · No credit card · Cancel any time