AWS access
Customer accounts use a scoped cross-account IAM role protected by an external ID. AWS onboarding runs through a customer-reviewed CloudFormation stack.
TRUST BOUNDARIES
Astroscale separates organization identity, source authorization, AWS infrastructure access, protected application configuration, and agent operations.
Customer accounts use a scoped cross-account IAM role protected by an external ID. AWS onboarding runs through a customer-reviewed CloudFormation stack.
Console and MCP access use organization membership and role checks. Remote MCP authentication uses OAuth; destructive operations require explicit confirmation.
Application containers run non-root with a read-only root filesystem and reduced Linux capabilities. Network and database access are explicitly configured.
Environment values are write-only in normal product surfaces and are encrypted before runtime delivery. Logs and API responses must not expose stored plaintext values.
Security concerns can be submitted through the beta access form with a request for a security follow-up. Do not include credentials, tokens, or sensitive customer data in the initial message.