Security

Security principles

Shipvise runs code created by customers and AI tools. That is why the platform is built around the following security principles.

Shipvise is in public beta. The scope of these protections may vary by plan and product stage, so availability is stated directly alongside the relevant feature or plan.

Isolation

The platform is designed with logical environment separation, limited privileges and network policies. This is not physically separate hardware or a separate kernel for every customer; the effectiveness of each control depends on the actually deployed cluster.

Least privilege

The runtime is designed for non-root execution, blocked privilege escalation, restricted capabilities and resource limits. A specific control applies only where it is actually deployed and verified in that environment.

Ephemeral build workspaces

Build infrastructure for untrusted code must use short-lived workspaces, separation from the sensitive control plane, limited privileges, resource limits and proportionate network restrictions.

Secret handling

Runtime secrets should be separate from source and build artifacts. Ordinary customer APIs should not return them in plaintext or intentionally write them to logs or AI prompts; the production path must be completed and verified before the public MVP.

Audit trail

Shipvise records selected technical and security-relevant operations when the application audits that function. It does not claim a complete cryptographically immutable audit of every administrative action.

Release immutability

The release model is designed around a specific OCI artifact identified by an immutable digest. This improves traceability but does not guarantee that the artifact is correct or secure.

Explicit production approval

Nothing reaches production without a person approving it. An AI agent connected through MCP can prepare a release but cannot promote it.

Rollback

Any previous release can be restored without a rebuild, which keeps recovery fast and predictable.

EU operation

The platform is operated from the EU by David Hošek under the Shipvise by Progity brand. Shipvise-managed environments run in the Czech Republic on infrastructure from WEDOS Internet, a.s. Customer-managed production can remain in the customer’s own region and infrastructure.

Reporting a problem

If you believe you have found a vulnerability in Shipvise, write to security@shipvise.com. Tell us what you did, what happened, and how we can reproduce it. We will confirm receipt and keep you informed.

Your AI built the application. Shipvise helps you run it for real.

Bring the project to Shipvise, verify the release on staging and move it through a controlled path to production. Keep your infrastructure or use a Shipvise-managed environment.