Home / Companies / Nango / Blog / Post Details
Content Deep Dive

How Nango runs untrusted customer code at scale

Blog post from Nango

Post Details
Company
Date Published
Author
Ross McEwan
Word Count
1,503
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

Nango is a code-first platform that enables customers to build API integrations with services like Salesforce and Slack, handling over 150 million functions monthly. Initially, customer code was run in a Node.js sandbox called vm2, but security vulnerabilities prompted Nango to isolate code execution through a dedicated runner model, later transitioning to AWS Lambda for improved resource management and observability. Lambda's hardware-virtualized microVMs offer stronger isolation, though challenges remain, particularly with tenant isolation since shared environments could pose security risks. To address this, Nango implemented per-customer Lambda functions, reducing the risk of cross-customer data exposure. Despite the increased rate of cold starts, this approach prioritizes security while maintaining functionality. The company is exploring further isolation enhancements, emphasizing the importance of a robust sandbox and resumable workloads to manage untrusted code securely.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Serverless 15 1,008 229 94 -44%
Secrets Management 2 2,476 387 132 +15%
AI Agents 1 6,005 1,359 264 +22%
Observability 1 4,166 768 194 +22%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.