Home / Companies / Ngrok / Blog / July 2022

July 2022 Summaries

2 posts from Ngrok

Filter
Month: Year:
Post Summaries Back to Blog
During the author's tenure at Okta, they became deeply familiar with OAuth 2.0, initially through their involvement in the beta program for API Access Management, which functioned as "OAuth as a Service." Despite initially only having a superficial understanding of OAuth, they immersed themselves in the technical specifications, learning the intricacies of scopes, grant types, and JWTs. Later, a demonstration by ngrok's CEO showcased the ease of implementing OAuth 2.0 using ngrok, which acts as a lightweight policy enforcement point by managing access tokens at the edge, thereby simplifying integration with various OAuth providers such as Google, Facebook, Github, and Microsoft. The process allows user identity information to be attached to requests, facilitating authentication and session management without altering the underlying application. The capability extends to custom OAuth providers, like Okta, enabling organizations to unify their security policies across diverse systems, including legacy and IoT devices. The author expresses admiration for ngrok's flexibility and its potential to further explore additional use cases, public and private OAuth providers, and features such as ID tokens and refresh token handling, inviting feedback and collaboration from the community.
Jul 26, 2022 802 words in the original blog post.
Ngrok has successfully completed its SOC 2 Type 2 audit with no findings, confirming that its processes effectively protect system and customer data. This audit follows their earlier SOC 2 Type 1 audit, with Type 1 assessing the presence of processes and Type 2 ensuring their daily execution. The completion of this audit affirms the security measures in place, such as multi-factor authentication, access reviews, code reviews, and automated deployments, all designed to enhance system security and operational integrity. While this achievement does not alter daily operations, it validates the robustness of Ngrok's security practices and sets a foundation for pursuing further compliance certifications like ISO/IEC 27001, HIPAA, and PCI DSS. Conducted by BARR Advisory, a specialist in cloud-based security and compliance for SaaS companies, the audit underscores Ngrok's commitment to maintaining high standards in cybersecurity and compliance, meeting diverse regulatory and customer needs. All reports are accessible through the ngrok security and trust portal, and customers can request additional compliance certifications as needed.
Jul 20, 2022 456 words in the original blog post.