Humanitec Security
Disclosure: We may earn a commission if you purchase through this link, at no extra cost to you. Learn more.
View Humanitec Security Documentation
Review Humanitec's compliance certifications, audit logs, access controls, and security architecture.
Enterprise-grade security.
Humanitec Security Overview
Humanitec focuses on workload orchestration security: Score spec validation, environment isolation, RBAC, and integration with cloud provider security. Platform API and CLI enforce authentication and authorization.
Authentication and SSO
OIDC integration (Okta, Azure AD, Google, Keycloak, custom). SAML 2.0 (Enterprise). API tokens for CLI/CI with scopes. Short-lived tokens with refresh. Organization and project-level access.
Authorization
RBAC with Organization Admin, Project Admin, Developer, Viewer roles. Resource-level permissions for environments, applications, workloads. Team-based access control. API token scopes for CI/CD automation.
Environment Isolation
Each environment (dev, staging, prod) is a separate Kubernetes namespace or cluster. Network policies, resource quotas, and RBAC isolate workloads. Delta engine prevents configuration drift. Ephemeral environments per PR with automatic cleanup.
Secrets and Configuration
Humanitec does not store secrets — integrates with cloud provider secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, HashiCorp Vault). Score spec references secrets by name; values injected at deployment. No secrets in Git.
Compliance
SOC 2 Type II. GDPR/CCPA. Encryption at rest and in transit. Audit logging (Enterprise). Data residency options. Vendor security questionnaire support. Penetration testing and bug bounty.
Compare Humanitec with Alternatives
See how Humanitec stacks up against competitors across features, pricing, and user reviews.
Trusted by thousands of DevOps teams. Read verified reviews before you buy.
We may earn a commission. Learn more