Can anyone comment on the security implications of using a service like this, render.com, fly.io, etc vs. rolling your own infra on AWS EC2 and friends?
On the other hand, many PaaS providers obfuscate their security implementation, and ultimately your data could be compromised by their mistakes. Things you should look for when evaluating PaaS providers:
- How are resources, networks, etc. separated/isolated per customer?
- What are YOUR security responsibilities on the platform?
- How transparent is the provider about their security controls? Do they have security whitepapers, SOC 2 reports, etc. that are transparent and legit? Better yet, can they prove to you in the product how security controls are being implemented?
Disclaimer: I'm the CEO and founder of Aptible [1], a PaaS specifically built to meet and prove security requirements for companies in regulated/high-compliance environments.
[0] https://aws.amazon.com/compliance/shared-responsibility-mode...