Trust
Security at Commray
Last updated: March 2026
At Commray, security is a core part of how we design, operate, and improve our platform. Because customers trust us with monitoring, observability, and operational data, we work to protect systems, accounts, and customer information using layered technical and organizational safeguards.
This page provides an overview of our current security practices and operational approach.
Infrastructure Security
Commray is deployed using modern cloud infrastructure providers designed to support secure, scalable, and reliable services.
We use industry-standard protections including:
- HTTPS/TLS encryption for data in transit
- Network isolation and firewall protections
- Environment-based access controls
- Managed infrastructure and cloud security tooling
- Continuous platform monitoring and logging
Account Security
Commray helps protect customer accounts through:
- Encrypted authentication flows
- Session and access controls
- Role-based access capabilities (available on supported plans)
- Secure password handling practices
- Workspace-level data isolation
Customers are responsible for maintaining the confidentiality of their credentials and managing authorized access to their workspace.
Data Protection
Customer data submitted to Commray is logically isolated by workspace and processed only for the purpose of operating and improving the Services.
We implement safeguards designed to reduce the risk of:
- Unauthorized access
- Data exposure
- Platform abuse
- Infrastructure misuse
Commray does not sell customer data.
Encryption
Commray uses encryption technologies designed to protect data:
- Data in transit is protected using HTTPS/TLS
- Sensitive credentials and secrets are handled using secure storage and restricted access practices
Monitoring & Operational Visibility
As an observability platform, Commray continuously monitors service health, operational metrics, platform activity, and infrastructure events to help identify reliability or security issues.
This includes monitoring for:
- Service disruptions
- Abnormal usage patterns
- Authentication anomalies
- Infrastructure-level issues
Access Controls
Access to production systems is limited to authorized personnel and protected through authentication and access management controls.
We follow the principle of least privilege where reasonably applicable.
Vulnerability Management
Commray works to identify and address security risks through:
- Dependency and package updates
- Infrastructure patching
- Internal testing and validation
- Monitoring and operational review
Security improvements are continuously incorporated into the platform as the product evolves.
Customer Responsibilities
Customers are responsible for:
- Managing user permissions within their workspace
- Securing API keys and credentials
- Reviewing data submitted to the platform
- Following their own internal security requirements and compliance obligations
Service Availability
We work to maintain reliable platform availability and operational stability, but no online service can guarantee uninterrupted availability.
Maintenance windows, infrastructure failures, third-party outages, or unforeseen security incidents may affect service operation.
Reporting Security Issues
If you believe you have discovered a security vulnerability or issue related to Commray, please contact:
Please include sufficient detail to help us investigate and respond appropriately.
Ongoing Improvements
Security is an ongoing process. As Commray grows, we expect to continue improving our security controls, operational practices, and compliance capabilities.