Security
How Cocobox keeps your credentials and data safe.
Security is the product. Everything below applies to every plan.
Credential storage
Database credentials, BYOK provider keys, and SSH keys are encrypted at rest with AES-256-GCM. Each workspace has a dedicated data-encryption key (DEK) wrapped by a KMS-managed key-encryption key (KEK). Decryption happens only in memory at request time and is never logged.
Hashes of keys you create (API keys) are stored as SHA-256; the cleartext is shown once at creation and never persisted.
Network
- All client traffic is TLS 1.2+ (TLS 1.3 preferred).
- HSTS is enforced on all
*.cocobox.iohosts (max-age=63072000; includeSubDomains; preload). - Outbound connections to your databases use TLS where supported; you control the SSL mode.
- Egress IPs from Cocobox’s compute are documented and can be allow-listed on enterprise plans.
Egress IPs
Cocobox egress is currently from these CIDRs (subject to change with 30 days notice):
54.241.16.0/24— us-west-254.85.128.0/24— us-east-135.205.64.0/22— eu-west-1
For static, dedicated egress IPs (so you can lock down a bastion or DB firewall to just your tenant), contact sales — included on Enterprise.
Authentication
- End-user auth is via Auth0 (OAuth 2.0 + OIDC). Supports Google, GitHub, email + password, and (Enterprise) SAML SSO.
- API auth is via
sk-coco-*keys, hashed at rest, scoped per API key. - MFA is available on every plan; required by default on Enterprise workspaces.
Multi-tenancy
Tenant isolation is enforced at the application layer. Every database query, every storage object lookup, and every cache fetch carries a workspace_id guard. Cross-tenant access is impossible without a deliberate breach of that layer (which is why we test it heavily, including via fuzzing).
DEKs are per-workspace, so even an application-layer compromise that bypassed the guard would yield ciphertext for other tenants.
SQL gate
For sensitive roles (read, run), every statement is parsed and classified before reaching your database. Statements that don’t match the role’s permitted set are rejected with sql_gate_blocked. The parser is dialect-aware and not regex-based; comment-disguised attacks are not effective.
Audit chain
Audit-log entries are append-only. Each entry includes the SHA-256 hash of the previous entry, forming a hash chain. The latest hash is published every 24h to a write-once log. Anyone with workspace audit access can verify the chain — instructions on request.
Data residency
Default region is us-west-2 (Oregon). Enterprise customers can pick us-east-1, eu-west-1, or ap-southeast-2. Audit logs and AI prompts/responses live in the same region as your workspace’s primary data.
Sub-processors
A current list of sub-processors is published at cocobox.io/legal/subprocessors. We notify customers 30 days before adding a new sub-processor.
Vulnerability reporting
Email security@cocobox.io. PGP key on the security page. We respond within 24 hours and run a public bug-bounty program — payouts up to $10,000 for critical findings.
Compliance
- SOC 2 Type II — audit completed; report under NDA.
- GDPR / UK GDPR — DPA available; standard contractual clauses for transfers.
- HIPAA — BAA available on Enterprise.
Incident response
- 24/7 on-call rotation.
- Public status page at status.cocobox.io.
- Postmortems for any user-impacting incident published within 14 days.