Encryption in transit and at rest
All customer traffic is served over TLS 1.3 with managed certificates. Connections to your origins use TLS by default, with optional mTLS for private origins. Stored configuration, logs and backups are encrypted at rest with AES-256.
Access control
Internal access to production systems requires hardware-backed multi-factor authentication, is granted on a least-privilege basis, and is reviewed quarterly. Every administrative action is logged and retained for one year.
- Hardware MFA required for all engineering access
- Just-in-time elevation with peer approval
- Quarterly access reviews and immediate offboarding
- Full audit trail of administrative actions
Resilience and DDoS mitigation
The AnyLB control plane runs in multiple regions behind an active-active configuration. Customer traffic is absorbed across Cloudflare's anycast network, with L3–L7 mitigation enabled by default. Control plane recovery objectives are RPO 15 minutes and RTO 60 minutes.
Compliance and disclosure
AnyLB maintains SOC 2 Type II attestation and aligns with ISO 27001 controls. We operate a coordinated vulnerability disclosure programme and acknowledge reports within 24 hours. Report issues to security@anylb.com.