Clear, explicit separation of security ownership between CUBE OneCare (application), Fly.io (infrastructure), and Cloudflare (edge). No ambiguity, no gaps.
Edge Encryption
TLS termination at the edge proxy with strict HTTPS enforcement
DNSSEC
DNS Security Extensions preventing DNS spoofing and cache poisoning
DDoS Protection
Enterprise-grade DDoS mitigation (L3/L4/L7) with automatic detection
Web Application Firewall
OWASP Top 10 ruleset, custom WAF rules, rate limiting
Bot Management
Machine learning-based bot detection and challenge mechanisms
Runtime Isolation
Container-level isolation with dedicated compute per service
Container Orchestration
Automated deployments, health checks, rolling updates, and rollbacks
Infrastructure Monitoring
Host-level metrics, resource utilization, container health monitoring
Network Segmentation
Private networking between services, no public IP for databases
Physical Security
Fly.io-hosted infrastructure with subprocessor security evidence mapped to SOC 2 controls
Application Logic
All business logic, workflow engines, and clinical decision support
PHI Processing
Protected Health Information handling, minimum necessary enforcement, de-identification
API Security
Authentication, authorization, input validation, rate limiting, request signing
FHIR Enforcement
HL7 FHIR R4 compliance, resource validation, consent-based access filtering
Authentication
JWT-based session management, MFA enforcement, SSO/SAML integration
Authorization
RBAC with role hierarchy, attribute-based access control, break-glass procedures
Audit Logging
HIPAA-aligned audit trails, insert-only PHI access logging
Encryption at Rest
AES-256-GCM field-level PHI encryption with per-tenant key isolation
Consent Management
Granular consent engine supporting HIPAA, GDPR, LGPD per-market requirements
AI Governance
Model routing, PHI isolation, cost governance, prompt sanitization, audit trails
| Security Domain | Cloudflare | Fly.io | CUBE |
|---|---|---|---|
| Edge Encryption / TLS | — | — | |
| DDoS Mitigation | — | — | |
| WAF / Bot Detection | — | — | |
| Container Isolation | — | — | |
| Infrastructure Monitoring | — | — | |
| Physical Data Center | — | — | |
| Application Logic | — | — | |
| Authentication / MFA | — | — | |
| Authorization / RBAC | — | — | |
| PHI Encryption | — | — | |
| FHIR API Compliance | — | — | |
| Audit Logging | — | — | |
| Consent Management | — | — | |
| Incident Response | — | ||
| Vulnerability Mgmt | — |
Our security team can walk you through the shared responsibility model in detail.
Contact Security Team