Skip to content
Magma Devs
Trust Center at Magma Devs

Security and trust for
production RPC infrastructure

Magma Devs is built for teams that depend on blockchain infrastructure in production. Our security program covers access controls, monitoring, secure development, incident response, compliance readiness, and customer trust documentation.

SOC 2 Type II certifiedISO/IEC 27001 certified
SOC 2 Type II & ISO/IEC 27001 certified
SOC 2 Type II· Certified
ISO/IEC 27001· Certified
DPA· Available
Security package· Available on request

How we approach security

The specifics your security team will ask about.

Access

  • Role-based access control
  • MFA for internal systems
  • Least-privilege permissions
  • Access reviews

Application security

  • Code review before production release
  • Dependency scanning
  • Secrets management
  • Protected branches

Infrastructure

  • Cloud infrastructure managed through controlled processes
  • Environment separation
  • Monitoring and alerting
  • Backup and recovery procedures

Data protection

  • Encryption in transit
  • Encryption at rest where applicable
  • Limited access to customer-related data
  • Logging controls

Incident response

  • Internal escalation procedures
  • On-call ownership
  • Customer communication process
  • Post-incident review

Vendor management

  • Review of critical vendors
  • Subprocessor tracking
  • Customer notification process where applicable
  • Vendor access controls

Compliance & assurance

We publish where we are, not where we wish we were.

SOC 2 Type II

Certified

Magma Devs is SOC 2 Type II certified. The report is available to qualified customers and prospects on request.

ISO/IEC 27001

Certified

Magma Devs is ISO/IEC 27001 certified for its information security management system. The certificate is available on request.

DPA

Available

A standard Data Processing Addendum is available for customers and prospects as part of vendor review.

Penetration testing

Available upon request

Audit reports are available under NDA, alongside our security package and DPA.

Everything your vendor review needs.

SOC 2 Type II report, ISO/IEC 27001 certificate, DPA, penetration test summary, subprocessor list, and a pre-filled security questionnaire (CAIQ). Request the package and complete your review in days, not weeks.

Request the security package

RPC in your DORA scope.

For regulated institutions, RPC providers are ICT third-party dependencies: concentration risk, resilience testing, incident evidence all apply. We map where Smart Router fits and what evidence it produces.

Take the Secure RPC Assessment

Report a vulnerability

If you believe you have found a security issue affecting Magma Devs, Smart Router, or our infrastructure, please contact us.

Acknowledgement
Within 24 hours

We ask researchers to act in good faith, avoid accessing customer data, avoid service disruption, and give us reasonable time to investigate and respond.

Need our full security package?

Our security package - SOC 2 Type II report, ISO/IEC 27001 certificate, DPA, security overview, and architecture materials - is available to qualified customers and prospects on request.