Security

Last updated: July 27, 2026

Security

Ravion has a deep commitment to data privacy and security in everything we do. We consistently monitor and ensure we meet our security and reliability standards.

Access to your AWS

Ravion never asks for or stores your AWS access keys. Instead, you grant Ravion access through a dedicated IAM role in your own account — you stay in control and can revoke access at any time from your AWS console.

Ravion obtains short-lived credentials directly from AWS STS using OIDC identity federation (AssumeRoleWithWebIdentity). Credentials are narrowly scoped to each specific operation, expire automatically within minutes, and are never written to logs. They are also pinned to Ravion’s infrastructure — even if a credential were ever exposed, it could not be used from anywhere outside our network.

Every access is tied to your account and recorded, so activity is fully auditable in your own CloudTrail.

Sensitive information

Ravion stores sensitive user information like environment variable secrets inside your AWS account.

Responsible Disclosure

Ravion encourages responsible disclosure of security vulnerabilities. Independent security experts and researchers can report security issues to security@ravion.com

Security Contact

Contact our Security Officer at security@ravion.com, and we’ll respond as soon as practical.

Compliance

SOC 2 Type II

Ravion is SOC 2 Type II compliant. The SOC 3 report is available on the Business plan, and the SOC 2 report is available under Enterprise contract.

HIPAA

Ravion is HIPAA ready. You typically only need a BAA with AWS because Ravion doesn’t store or process any of your user data. Reach out if you have questions.

GDPR

Refer to the “European Union and United Kingdom Data Subject Rights” section in our Privacy Policy.

Trust Center

View our Trust Center at trustcenter.flightcontrol.dev/.