Security reviewסקירת אבטחה

Written for the person who has to sign off on us. Everything below is a statement of fact about how the platform is built, not a marketing claim, and we will put any of it in a contract.

נכתב עבור מי שצריך לאשר אותנו. כל מה שלמטה הוא קביעת עובדה על אופן בניית הפלטפורמה, לא טענה שיווקית, ואנחנו מוכנים להכניס כל אחת מהן לחוזה.

Who you are contracting withעם מי אתם מתקשרים

IsraelInterhost Networks Ltd. Israeli entity, Israeli law, invoices in ILS.אינטרהוסט נטוורקס בע״מ. ישות ישראלית, דין ישראלי, חשבוניות בשקלים.
European UnionInterhost Networks B.V., KvK 91064333, Netherlands. Dutch law, EU jurisdiction, invoices in EUR.Interhost Networks B.V., KvK 91064333, הולנד. דין הולנדי, שיפוט אירופי, חשבוניות ביורו.
Operating historyInterhost has run production hosting for Israeli and European businesses for over two decades. Shipyard is a product on that network, not a startup renting one.אינטרהוסט מפעילה אירוח ייצור לעסקים ישראליים ואירופיים כבר יותר משני עשורים. Shipyard הוא מוצר על הרשת הזו, לא סטארטאפ ששוכר אחת.

Where the infrastructure isאיפה התשתית

Data handlingטיפול בנתונים

Customer contentSource, artifacts, logs, databases and volumes stay in the region selected for the project. No cross-region replication without an explicit written agreement.קוד, תוצרים, לוגים, מסדי נתונים ונפחים נשארים באזור שנבחר לפרויקט. אין שכפול בין-אזורי ללא הסכם כתוב מפורש.
Account metadataIdentity, org membership, billing and the audit index are stored in the EU.זהות, חברות בארגון, חיוב ואינדקס הביקורת מאוחסנים באיחוד האירופי.
Encryption at restVolumes and database storage encrypted. Environment variables additionally encrypted with per-organisation keys.נפחים ואחסון מסדי נתונים מוצפנים. משתני סביבה מוצפנים בנוסף עם מפתחות ייעודיים לארגון.
Encryption in transitTLS 1.2 minimum on every public endpoint, 1.3 preferred. HSTS enabled. Internal traffic on a per-organisation overlay.TLS 1.2 מינימום בכל נקודת קצה ציבורית, 1.3 מועדף. HSTS פעיל. תעבורה פנימית ברשת-על ייעודית לארגון.
SecretsNo read path exists. Not through the API, CLI, panel, MCP or support. We cannot show you your own secret value, and neither can an attacker holding your key.לא קיים מסלול קריאה. לא דרך ה-API, ה-CLI, הפאנל, MCP או התמיכה. אנחנו לא יכולים להראות לכם את ערך הסוד שלכם, וגם תוקף שמחזיק במפתח שלכם לא.
DeletionDeleting a project removes running instances immediately and purges artifacts, logs and backups within 30 days.מחיקת פרויקט מסירה מופעים רצים מיד ומוחקת תוצרים, לוגים וגיבויים תוך 30 יום.

Access controlבקרת גישה

Software supply chainשרשרת אספקת התוכנה

Every release is scanned before it can serve traffic: dependencies against known advisories at resolved versions, committed secrets, container surface, and configuration defaults. Critical findings block the release outright. The scan cannot be disabled for an organisation; the only escape is a per-finding, time-boxed exception granted by an owner with a stated reason, and it appears in the audit log.

כל שחרור נסרק לפני שהוא יכול לשרת תעבורה: תלויות מול התרעות ידועות בגרסאות שנפתרו, סודות שהוקומטו, משטח הקונטיינר וברירות מחדל של הגדרות. ממצאים קריטיים חוסמים את השחרור לחלוטין. אי אפשר לכבות את הסריקה לארגון; דלת החירום היחידה היא חריגה לממצא בודד, מוגבלת בזמן, שניתנת על ידי בעלים עם נימוק מוצהר, והיא מופיעה ביומן הביקורת.

Logging and retentionתיעוד ושמירה

Audit logDeploys, rollbacks, env writes, key lifecycle, role changes, security exceptions. Actor, time, source address, target. 12 months.פריסות, חזרות לאחור, כתיבות סביבה, מחזור חיי מפתחות, שינויי תפקיד, חריגות אבטחה. מבצע, זמן, כתובת מקור, יעד. 12 חודשים.
Application logsRetained 30 days, in region, exportable.נשמרים 30 יום, באזור, ניתנים לייצוא.
Request idsEvery API error carries a request_id that lets us locate the exact request during an investigation.כל שגיאת API נושאת request_id שמאפשר לנו לאתר את הבקשה המדויקת בחקירה.

Availability and supportזמינות ותמיכה

Certification status, stated plainlyמצב ההסמכה, בגילוי לב

Interhost operates under ISO 27001 aligned controls. Where a specific certificate, attestation or DPA is required for your procurement process, ask and we will tell you exactly what we hold today and what is in progress. We would rather lose a deal than imply a certification we do not have.

אינטרהוסט פועלת תחת בקרות בהתאמה ל-ISO 27001. היכן שנדרשת תעודה, אישור או DPA ספציפי לתהליך הרכש שלכם, שאלו ונאמר לכם בדיוק מה יש לנו היום ומה בתהליך. אנחנו מעדיפים להפסיד עסקה מאשר לרמוז על הסמכה שאין לנו.

Reporting a vulnerabilityדיווח על חולשה

security@interhost.net. Acknowledged within one business day. No NDA required before you report, and no legal threats for good-faith research.

security@interhost.net. אישור קבלה תוך יום עסקים אחד. לא נדרש הסכם סודיות לפני דיווח, ואין איומים משפטיים על מחקר בתום לב.

Questionnairesשאלוני אבטחה

Send yours to shipyard@interhost.net. We fill them in ourselves, we answer “no” where the answer is no, and we turn them around in days rather than weeks.

שלחו את שלכם ל-shipyard@interhost.net. אנחנו ממלאים אותם בעצמנו, עונים ”לא“ כשהתשובה היא לא, ומחזירים תוך ימים ולא שבועות.