Skip to content

Secure by Design

Enterprise-grade security from sandbox to production.

HarvardGoogleDuolingoStanfordOpenAITikTokMITNvidiaShopify

Defense in Depth

Security that scales with your company

Built-in security, compliance, governance, and visibility give enterprise teams the control they need.

Learn more about Restart for enterprise

SSO

SAML and OIDC with Okta, Azure AD, Google, and any compliant identity provider.

SCIM

Automated provisioning and deprovisioning synced from your identity provider.

Role-Based Access Control

Granular permissions for viewing, editing, and deploying across your org.

Private Deployments

Keep internal prototypes private. Control who can access what you build.

Audit Logging

Full visibility into who did what and when across your organization.

Security Center

Act on vulnerabilities in bulk across all apps in your organization.

Secure on all fronts

Independent layers of security work together to reduce risk at every level.

Isolated sandboxes, backend separation, built-in auth, supply chain protection, and pre-deploy scanning — working from day one.

Isolated Sandboxes

Hardened Linux containers with seccomp-bpf, migrating to microVMs for the strongest isolation available.

Backend Separation

A real backend, not just Row Level Security — true architectural separation between your app’s layers.

Dev/Prod Isolation

Forked development environments keep work-in-progress away from production until each change is ready to ship.

Built-in Auth

Managed authentication and secure session handling come standard in every app — nothing to wire up.

Supply Chain Protection

Dependencies are vetted and locked, guarding every build against compromised packages.

Pre-Deploy Scanning

Every application is scanned for vulnerabilities before it ever reaches production.

No cross-app access, transparent secret handling, and irrecoverable-proof backups.

Scoped Data Access

No cross-app access unless explicitly opted in. Each app’s data is invisible to every other app.

Secret Proxying

Credentials injected via a sidecar proxy at runtime — never stored in code, never visible to the AI Agent.

Continuous Backups

Daily backups with full version history — no change to your app or its data is ever unrecoverable.

Encryption Everywhere

Data is encrypted in transit and at rest, with keys managed and rotated automatically.

Zero trust architecture, per-customer cloud projects, and DDoS protection on every deployment.

Zero Trust

Mutual TLS, short-lived tokens, least-privilege access, and network segmentation platform-wide.

Per-Customer GCP

Every customer gets their own Google Cloud project — even on free tier. A real infrastructure boundary.

Cloud Armor

DDoS mitigation and web application firewall protection applied automatically to every deployment.

Bug bounties, penetration testing, AI red-teaming, and a hardening cycle for every incident.

Bug Bounty

Security researchers worldwide continuously test the platform through a public HackerOne bounty reward program.

Penetration Testing

Commissioned in-depth security reviews by Trail of Bits stress-test every layer of platform infrastructure.

AI Red-Teaming

An internal adversarial program continuously probes the platform and agents for prompt injection and abuse.

Incident Hardening

Every incident closes with a hardening cycle, so fixes land platform-wide instead of as one-off patches.

Founders

Building your first company? You’re already covered.

Security is built into every Restart company from day one, with enterprise-level protection included by default.

  • Pre-publish comprehensive security scanning with Security Agent.

  • Separate development and production databases mean changes in development never touch your company in production.

  • 24×7 watch over your apps for vulnerabilities in your dependencies with Restart Auto-Detect.

  • Automatic backups mean you can always roll back.

Compliant and certified

SOC 2 TYPE II GDPR ISO 27001

Learn more about our compliance progress

SOC 2 Type II, GDPR, and ISO 27001 programs are underway — certifications are published here when they are held.

Frequently asked questions

Where does my company’s data live?

Every customer gets their own Google Cloud project — even on the free tier — so your company runs inside a real infrastructure boundary. Data is encrypted in transit and at rest, with keys managed and rotated automatically.

How is my company isolated from other customers?

Apps run in hardened, isolated sandboxes inside your own cloud project, and data access is scoped: one app’s data is invisible to every other app, with no cross-app access unless you explicitly opt in.

How are secrets and API credentials handled?

Credentials are injected through a sidecar proxy at runtime — never stored in your code, and never visible to the AI agent.

Does Restart scan my apps for vulnerabilities?

Yes. Security Agent reviews code as it’s built and scans the full application before deployment, while Restart Auto-Detect keeps a 24×7 watch over your dependencies for newly disclosed vulnerabilities.

What keeps development changes away from production?

Development runs in forked environments with separate databases. Nothing you try in development touches your company in production until the change is ready to ship.

Who controls what gets published?

You do. Nothing publishes without your confirmation, and every application is scanned for vulnerabilities before it ever reaches production.

What happens if something goes wrong?

Automatic daily backups with full version history mean no change to your app or its data is ever unrecoverable — you can always roll back.

Is Restart SOC 2, GDPR, or ISO 27001 certified?

SOC 2 Type II, GDPR, and ISO 27001 programs are underway. We publish certifications here when they are held — not before. Questions for a security review are welcome at security@skarmy.ai.

How is the platform itself tested?

Through a public HackerOne bug bounty, commissioned penetration testing by Trail of Bits, and an internal AI red-team that continuously probes for prompt injection and abuse. Every incident closes with a platform-wide hardening cycle.