Secure by Design
Enterprise-grade security from sandbox to production.
Defense in Depth
Security that scales with your company
Built-in security, compliance, governance, and visibility give enterprise teams the control they need.
Learn more about Restart for enterpriseSSO
SAML and OIDC with Okta, Azure AD, Google, and any compliant identity provider.
SCIM
Automated provisioning and deprovisioning synced from your identity provider.
Role-Based Access Control
Granular permissions for viewing, editing, and deploying across your org.
Private Deployments
Keep internal prototypes private. Control who can access what you build.
Audit Logging
Full visibility into who did what and when across your organization.
Security Center
Act on vulnerabilities in bulk across all apps in your organization.
Secure on all fronts
Independent layers of security work together to reduce risk at every level.
Isolated sandboxes, backend separation, built-in auth, supply chain protection, and pre-deploy scanning — working from day one.
Isolated Sandboxes
Hardened Linux containers with seccomp-bpf, migrating to microVMs for the strongest isolation available.
Backend Separation
A real backend, not just Row Level Security — true architectural separation between your app’s layers.
Dev/Prod Isolation
Forked development environments keep work-in-progress away from production until each change is ready to ship.
Built-in Auth
Managed authentication and secure session handling come standard in every app — nothing to wire up.
Supply Chain Protection
Dependencies are vetted and locked, guarding every build against compromised packages.
Pre-Deploy Scanning
Every application is scanned for vulnerabilities before it ever reaches production.
No cross-app access, transparent secret handling, and irrecoverable-proof backups.
Scoped Data Access
No cross-app access unless explicitly opted in. Each app’s data is invisible to every other app.
Secret Proxying
Credentials injected via a sidecar proxy at runtime — never stored in code, never visible to the AI Agent.
Continuous Backups
Daily backups with full version history — no change to your app or its data is ever unrecoverable.
Encryption Everywhere
Data is encrypted in transit and at rest, with keys managed and rotated automatically.
Zero trust architecture, per-customer cloud projects, and DDoS protection on every deployment.
Zero Trust
Mutual TLS, short-lived tokens, least-privilege access, and network segmentation platform-wide.
Per-Customer GCP
Every customer gets their own Google Cloud project — even on free tier. A real infrastructure boundary.
Cloud Armor
DDoS mitigation and web application firewall protection applied automatically to every deployment.
Bug bounties, penetration testing, AI red-teaming, and a hardening cycle for every incident.
Bug Bounty
Security researchers worldwide continuously test the platform through a public HackerOne bounty reward program.
Penetration Testing
Commissioned in-depth security reviews by Trail of Bits stress-test every layer of platform infrastructure.
AI Red-Teaming
An internal adversarial program continuously probes the platform and agents for prompt injection and abuse.
Incident Hardening
Every incident closes with a hardening cycle, so fixes land platform-wide instead of as one-off patches.
Founders
Building your first company? You’re already covered.
Security is built into every Restart company from day one, with enterprise-level protection included by default.
-
Pre-publish comprehensive security scanning with Security Agent.
-
Separate development and production databases mean changes in development never touch your company in production.
-
24×7 watch over your apps for vulnerabilities in your dependencies with Restart Auto-Detect.
-
Automatic backups mean you can always roll back.
Compliant and certified
Learn more about our compliance progress
SOC 2 Type II, GDPR, and ISO 27001 programs are underway — certifications are published here when they are held.
Frequently asked questions
Where does my company’s data live?
Every customer gets their own Google Cloud project — even on the free tier — so your company runs inside a real infrastructure boundary. Data is encrypted in transit and at rest, with keys managed and rotated automatically.
How is my company isolated from other customers?
Apps run in hardened, isolated sandboxes inside your own cloud project, and data access is scoped: one app’s data is invisible to every other app, with no cross-app access unless you explicitly opt in.
How are secrets and API credentials handled?
Credentials are injected through a sidecar proxy at runtime — never stored in your code, and never visible to the AI agent.
Does Restart scan my apps for vulnerabilities?
Yes. Security Agent reviews code as it’s built and scans the full application before deployment, while Restart Auto-Detect keeps a 24×7 watch over your dependencies for newly disclosed vulnerabilities.
What keeps development changes away from production?
Development runs in forked environments with separate databases. Nothing you try in development touches your company in production until the change is ready to ship.
Who controls what gets published?
You do. Nothing publishes without your confirmation, and every application is scanned for vulnerabilities before it ever reaches production.
What happens if something goes wrong?
Automatic daily backups with full version history mean no change to your app or its data is ever unrecoverable — you can always roll back.
Is Restart SOC 2, GDPR, or ISO 27001 certified?
SOC 2 Type II, GDPR, and ISO 27001 programs are underway. We publish certifications here when they are held — not before. Questions for a security review are welcome at security@skarmy.ai.
How is the platform itself tested?
Through a public HackerOne bug bounty, commissioned penetration testing by Trail of Bits, and an internal AI red-team that continuously probes for prompt injection and abuse. Every incident closes with a platform-wide hardening cycle.