Security reviewסקירת אבטחה
Written for the person who has to sign off on us. Everything below is a statement of fact about how the platform is built, not a marketing claim, and we will put any of it in a contract.
נכתב עבור מי שצריך לאשר אותנו. כל מה שלמטה הוא קביעת עובדה על אופן בניית הפלטפורמה, לא טענה שיווקית, ואנחנו מוכנים להכניס כל אחת מהן לחוזה.
Who you are contracting withעם מי אתם מתקשרים
IsraelInterhost Networks Ltd. Israeli entity, Israeli law, invoices in ILS.אינטרהוסט נטוורקס בע״מ. ישות ישראלית, דין ישראלי, חשבוניות בשקלים.European UnionInterhost Networks B.V., KvK 91064333, Netherlands. Dutch law, EU jurisdiction, invoices in EUR.Interhost Networks B.V., KvK 91064333, הולנד. דין הולנדי, שיפוט אירופי, חשבוניות ביורו.Operating historyInterhost has run production hosting for Israeli and European businesses for over two decades. Shipyard is a product on that network, not a startup renting one.אינטרהוסט מפעילה אירוח ייצור לעסקים ישראליים ואירופיים כבר יותר משני עשורים. Shipyard הוא מוצר על הרשת הזו, לא סטארטאפ ששוכר אחת.Where the infrastructure isאיפה התשתית
- il-tlv — Tel Aviv, Israel. Interhost-operated facility, our own racks and network.il-tlv — תל אביב, ישראל. מתקן בהפעלת אינטרהוסט, המדפים והרשת שלנו.
- nl-ams — Amsterdam, Netherlands. Serverius facilities, Interhost Networks B.V. equipment.nl-ams — אמסטרדם, הולנד. מתקני Serverius, ציוד של Interhost Networks B.V.
- We own the address space, the routers and the transit. There is no hyperscaler underneath this, which is why residency is enforceable rather than promised.אנחנו הבעלים של מרחב הכתובות, הנתבים והטרנזיט. אין ענן-ענק מתחת לזה, ולכן מיקום הנתונים ניתן לאכיפה ולא רק מובטח.
- 1.2 Tbps of network capacity with DDoS mitigation at the edge.1.2 טרהביט לשנייה של קיבולת רשת עם הגנת DDoS בקצה.
Data handlingטיפול בנתונים
Customer contentSource, artifacts, logs, databases and volumes stay in the region selected for the project. No cross-region replication without an explicit written agreement.קוד, תוצרים, לוגים, מסדי נתונים ונפחים נשארים באזור שנבחר לפרויקט. אין שכפול בין-אזורי ללא הסכם כתוב מפורש.Account metadataIdentity, org membership, billing and the audit index are stored in the EU.זהות, חברות בארגון, חיוב ואינדקס הביקורת מאוחסנים באיחוד האירופי.Encryption at restVolumes and database storage encrypted. Environment variables additionally encrypted with per-organisation keys.נפחים ואחסון מסדי נתונים מוצפנים. משתני סביבה מוצפנים בנוסף עם מפתחות ייעודיים לארגון.Encryption in transitTLS 1.2 minimum on every public endpoint, 1.3 preferred. HSTS enabled. Internal traffic on a per-organisation overlay.TLS 1.2 מינימום בכל נקודת קצה ציבורית, 1.3 מועדף. HSTS פעיל. תעבורה פנימית ברשת-על ייעודית לארגון.SecretsNo read path exists. Not through the API, CLI, panel, MCP or support. We cannot show you your own secret value, and neither can an attacker holding your key.לא קיים מסלול קריאה. לא דרך ה-API, ה-CLI, הפאנל, MCP או התמיכה. אנחנו לא יכולים להראות לכם את ערך הסוד שלכם, וגם תוקף שמחזיק במפתח שלכם לא.DeletionDeleting a project removes running instances immediately and purges artifacts, logs and backups within 30 days.מחיקת פרויקט מסירה מופעים רצים מיד ומוחקת תוצרים, לוגים וגיבויים תוך 30 יום.Access controlבקרת גישה
- Four roles: owner, admin, developer, viewer. Production deploy and rollback require admin or owner.ארבעה תפקידים: בעלים, מנהל, מפתח, צופה. פריסה לייצור וחזרה לאחור דורשות מנהל או בעלים.
- API keys carry explicit scopes and can be limited to a single project and given an expiry. A key never exceeds the role of the member who created it.מפתחות API נושאים הרשאות מפורשות וניתן להגביל אותם לפרויקט אחד ולתת להם תפוגה. מפתח לעולם לא חורג מהתפקיד של החבר שיצר אותו.
- AI agents are treated as members with keys, not as an unmodelled side channel. The audit log names the key that acted.סוכני AI מטופלים כחברים עם מפתחות, לא כערוץ צדדי לא ממודל. יומן הביקורת נוקב במפתח שפעל.
- Interhost staff do not have standing access to customer environment variables or database contents. Access for a support case is time-boxed, requires customer initiation, and is logged.לעובדי אינטרהוסט אין גישה קבועה למשתני סביבה או לתוכן מסדי נתונים של לקוחות. גישה לצורך פנייה היא מוגבלת בזמן, דורשת יוזמת הלקוח, ונרשמת.
Software supply chainשרשרת אספקת התוכנה
Every release is scanned before it can serve traffic: dependencies against known advisories at resolved versions, committed secrets, container surface, and configuration defaults. Critical findings block the release outright. The scan cannot be disabled for an organisation; the only escape is a per-finding, time-boxed exception granted by an owner with a stated reason, and it appears in the audit log.
כל שחרור נסרק לפני שהוא יכול לשרת תעבורה: תלויות מול התרעות ידועות בגרסאות שנפתרו, סודות שהוקומטו, משטח הקונטיינר וברירות מחדל של הגדרות. ממצאים קריטיים חוסמים את השחרור לחלוטין. אי אפשר לכבות את הסריקה לארגון; דלת החירום היחידה היא חריגה לממצא בודד, מוגבלת בזמן, שניתנת על ידי בעלים עם נימוק מוצהר, והיא מופיעה ביומן הביקורת.
Logging and retentionתיעוד ושמירה
Audit logDeploys, rollbacks, env writes, key lifecycle, role changes, security exceptions. Actor, time, source address, target. 12 months.פריסות, חזרות לאחור, כתיבות סביבה, מחזור חיי מפתחות, שינויי תפקיד, חריגות אבטחה. מבצע, זמן, כתובת מקור, יעד. 12 חודשים.Application logsRetained 30 days, in region, exportable.נשמרים 30 יום, באזור, ניתנים לייצוא.Request idsEvery API error carries a request_id that lets us locate the exact request during an investigation.כל שגיאת API נושאת request_id שמאפשר לנו לאתר את הבקשה המדויקת בחקירה.Availability and supportזמינות ותמיכה
- Platform status is published publicly and monitored from multiple external vantage points, not only from inside our own network.סטטוס הפלטפורמה מתפרסם בפומבי ומנוטר מכמה נקודות תצפית חיצוניות, לא רק מתוך הרשת שלנו.
- Team plan: email support with a one business day response target.מסלול Team: תמיכה במייל עם יעד תגובה של יום עסקים אחד.
- Sovereign plan: contractual SLA, named engineer and a 24/7 escalation path to the network operations team.מסלול Sovereign: SLA חוזי, מהנדס ייעודי ומסלול הסלמה 24/7 לצוות תפעול הרשת.
Interhost operates under ISO 27001 aligned controls. Where a specific certificate, attestation or DPA is required for your procurement process, ask and we will tell you exactly what we hold today and what is in progress. We would rather lose a deal than imply a certification we do not have.
אינטרהוסט פועלת תחת בקרות בהתאמה ל-ISO 27001. היכן שנדרשת תעודה, אישור או DPA ספציפי לתהליך הרכש שלכם, שאלו ונאמר לכם בדיוק מה יש לנו היום ומה בתהליך. אנחנו מעדיפים להפסיד עסקה מאשר לרמוז על הסמכה שאין לנו.
Reporting a vulnerabilityדיווח על חולשה
security@interhost.net. Acknowledged within one business day. No NDA required before you report, and no legal threats for good-faith research.
security@interhost.net. אישור קבלה תוך יום עסקים אחד. לא נדרש הסכם סודיות לפני דיווח, ואין איומים משפטיים על מחקר בתום לב.
Questionnairesשאלוני אבטחה
Send yours to shipyard@interhost.net. We fill them in ourselves, we answer “no” where the answer is no, and we turn them around in days rather than weeks.
שלחו את שלכם ל-shipyard@interhost.net. אנחנו ממלאים אותם בעצמנו, עונים ”לא“ כשהתשובה היא לא, ומחזירים תוך ימים ולא שבועות.