Heroku Private Spaces Security Features: The Complete List (and 6 Controls You Can't Add)
Blog post from Qovery
Heroku Private Spaces provide isolated, single-region environments within Salesforce-owned AWS infrastructure, offering stable outbound IPs, CIDR-based Trusted IP Ranges, IPSec VPN, VPC peering, AWS PrivateLink for selected data services, internal-only routing, dedicated dynos, centralized logging, and related networking controls, though feature availability can differ between the legacy Cedar and newer Fir generations. Heroku Shield Private Spaces add controls aimed at regulated workloads, including encrypted ephemeral storage, Shield data services, restricted interactive sessions and external database access, space-wide log drains, and compliance support for HIPAA through a Business Associate Agreement and PCI-covered applications. The article emphasizes that Private Spaces do not provide customer access to the underlying cloud account or customer-managed encryption keys, security groups, network ACLs, VPC flow logs, infrastructure-level CloudTrail, native WAF or IDS controls, broad regional choice, cloud committed-use discounts, or guaranteed private perimeters for every third-party add-on. It frames the choice as a tradeoff between Heroku’s low operational burden and rapid compliance path versus deploying in an organization’s own cloud account, where teams gain direct control of keys, logs, networks, regions, and billing discounts but assume greater platform-management responsibility.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Kubernetes | 15 | 956 | 75 | 30 | -73% |
| Platform Engineering | 6 | 358 | 65 | 25 | -70% |
| Secrets Management | 4 | 451 | 99 | 43 | -80% |
| Developer Experience | 3 | 131 | 58 | 24 | -72% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.