Do you have any evidence Render actually takes security seriously?
Not shitting on their platform, I actually never used it, I just think as an industry we should be way past the point we trust platforms by default.
Do you have any evidence Render actually takes security seriously?
Not shitting on their platform, I actually never used it, I just think as an industry we should be way past the point we trust platforms by default.
They plainly lied. Responses take weeks and are very incomplete. They have so few people they can't possibly run a secure, stable system anymore. They don't have a plan or backing from sfdc to get back to a solid foundation.
I can't speak to competitors but I can say with certainty that Heroku is simply not an option for you anymore. Whether that means you use another PaaS or fire up an EC2 instance yourself you must move away at this point.
That's a great point and I fully agree.
I'm struggling to come up with reliable ways of checking security of the companies I'm not familiar with. It's not like I can rely on their landing page. And they are likely not on the market long enough to see how they responded to past security incidents.
The only thing I can think of is checking how they handle registration and logins - but it's not that strong of a signal anyway. Does anyone have other ideas?