Last updated: July 27, 2026
Ravion has a deep commitment to data privacy and security in everything we do. We consistently monitor and ensure we meet our security and reliability standards.
Ravion never asks for or stores your AWS access keys. Instead, you grant Ravion access through a dedicated IAM role in your own account — you stay in control and can revoke access at any time from your AWS console.
Ravion obtains short-lived credentials directly from AWS STS using OIDC identity federation (AssumeRoleWithWebIdentity). Credentials are narrowly scoped to each specific operation, expire automatically within minutes, and are never written to logs. They are also pinned to Ravion’s infrastructure — even if a credential were ever exposed, it could not be used from anywhere outside our network.
Every access is tied to your account and recorded, so activity is fully auditable in your own CloudTrail.
Ravion stores sensitive user information like environment variable secrets inside your AWS account.
Ravion encourages responsible disclosure of security vulnerabilities. Independent security experts and researchers can report security issues to security@ravion.com
Contact our Security Officer at security@ravion.com, and we’ll respond as soon as practical.
Ravion is SOC 2 Type II compliant. The SOC 3 report is available on the Business plan, and the SOC 2 report is available under Enterprise contract.
Ravion is HIPAA ready. You typically only need a BAA with AWS because Ravion doesn’t store or process any of your user data. Reach out if you have questions.
Refer to the “European Union and United Kingdom Data Subject Rights” section in our Privacy Policy.
View our Trust Center at trustcenter.flightcontrol.dev/.