Blacksmith is SOC2 Type 1 compliant
Blog post from Blacksmith
Blacksmith announced that it has achieved SOC 2 Type 1 compliance following an independent audit of its internal controls, reinforcing its stated commitment to security and data protection for its CI platform. The company also reports hiring an independent security consultant for penetration testing and implementing disaster-recovery measures for its databases and backend infrastructure. Blacksmith says it retains only job-execution metadata, its GitHub app cannot access customer secrets, and it uses single-use just-in-time GitHub tokens to limit credential exposure. GitHub Actions workloads run in isolated, ephemeral Firecracker virtual machines with hardware isolation, memory-safe components, and state destruction after each job. The company plans to continue using independent audits and consultants to assess security and offers its SOC 2 Type 1 report upon request.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 1 | 788 | 122 | 68 | -23% |
| Serverless | 1 | 595 | 126 | 76 | -42% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.