Trust CenterSecurityComplianceInfrastructureStatus
Trust Center · Infrastructure

Where MachineCert runs.

MachineCert is deployable as SaaS, private cloud, on-premises, and air-gapped. Our SaaS runs on DigitalOcean, whose data centers maintain independently audited security and physical controls.

Shared responsibility

Who is responsible
for what.

Security is a shared responsibility between the infrastructure provider, MachineCert, and you. Here is how it divides for the SaaS deployment.

DigitalOcean (provider)
Physical securitydata centers
Host & networkaudited controls
MachineCertapp · data · access
Responsibilities
Providerphysical · host · network
MachineCertapp security · encryption · access
Youusers · roles · data policy
Infrastructure security

How the platform is run.

Encryption

TLS 1.3 in transit, AES-256 at rest, managed key rotation.

Physical security

Inherited from DigitalOcean’s audited, access-controlled data centers.

Backup & resiliency

Regular backups, redundancy, and tested recovery procedures.

Isolation

Hardened, isolated environments with least-privilege access.

Deployment models

SaaS, private cloud, on-prem, and air-gapped options.

Monitoring

Continuous security monitoring and alerting.

Deployment options

Run it your way.

SaaS

Fully managed on DigitalOcean — fastest to value.

Private cloud

Deployed in your own cloud account for tighter control.

On-premises / air-gapped

Run entirely within your environment, including isolated networks.

Security questions?
We’re glad to answer.

Request documentation, our subprocessor list, or a conversation with the team that builds MachineCert.