Security and trust for
production RPC infrastructure
Magma Devs is built for teams that depend on blockchain infrastructure in production. Our security program covers access controls, monitoring, secure development, incident response, compliance readiness, and customer trust documentation.


How we approach security
The specifics your security team will ask about.
Access
- Role-based access control
- MFA for internal systems
- Least-privilege permissions
- Access reviews
Application security
- Code review before production release
- Dependency scanning
- Secrets management
- Protected branches
Infrastructure
- Cloud infrastructure managed through controlled processes
- Environment separation
- Monitoring and alerting
- Backup and recovery procedures
Data protection
- Encryption in transit
- Encryption at rest where applicable
- Limited access to customer-related data
- Logging controls
Incident response
- Internal escalation procedures
- On-call ownership
- Customer communication process
- Post-incident review
Vendor management
- Review of critical vendors
- Subprocessor tracking
- Customer notification process where applicable
- Vendor access controls
Compliance & assurance
We publish where we are, not where we wish we were.
SOC 2 Type II
CertifiedMagma Devs is SOC 2 Type II certified. The report is available to qualified customers and prospects on request.
ISO/IEC 27001
CertifiedMagma Devs is ISO/IEC 27001 certified for its information security management system. The certificate is available on request.
DPA
AvailableA standard Data Processing Addendum is available for customers and prospects as part of vendor review.
Penetration testing
Available upon requestAudit reports are available under NDA, alongside our security package and DPA.
Everything your vendor review needs.
SOC 2 Type II report, ISO/IEC 27001 certificate, DPA, penetration test summary, subprocessor list, and a pre-filled security questionnaire (CAIQ). Request the package and complete your review in days, not weeks.
Request the security packageRPC in your DORA scope.
For regulated institutions, RPC providers are ICT third-party dependencies: concentration risk, resilience testing, incident evidence all apply. We map where Smart Router fits and what evidence it produces.
Take the Secure RPC AssessmentReport a vulnerability
If you believe you have found a security issue affecting Magma Devs, Smart Router, or our infrastructure, please contact us.
We ask researchers to act in good faith, avoid accessing customer data, avoid service disruption, and give us reasonable time to investigate and respond.
Need our full security package?
Our security package - SOC 2 Type II report, ISO/IEC 27001 certificate, DPA, security overview, and architecture materials - is available to qualified customers and prospects on request.