Fly.io Deployment Security Review
A Fly.io organisation has only two roles, and Member already reaches every app’s secrets, volumes and Machines. We test the roles, tokens and network exposure your team actually configured, not Fly.io’s platform. CREST-certified testers, fixed price from £2,320 for a 2-day single-org scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Fly.io organisations run on just two roles, Member and Admin, and a Member can already create apps and manage every app’s secrets, volumes and Machines in the org.
A Fly.io organisation is only as secure as the roles and tokens your team has issued
Fly.io documents just two organisation roles, Member and Admin, and the difference is coarse rather than granular: a Member can already create and destroy apps, deploy new versions, manage secrets, volumes and Machines, and reach the org’s private network, while only an Admin can invite or remove users, view or update billing, and delete the organisation outright. Fly.io’s own advice for narrowing that reach is to split environments into separate organisations and to hand out read-only tokens rather than Member access to anyone who only needs to look.
Outside individual logins, the credential Fly.io calls the all-powerful auth token is a short-lived personal access token created automatically on every login, and Fly.io’s current guidance is to stop wiring it into CI or third-party services in favour of a macaroon built with the narrowest scope that will work: a single app, a whole org, or read-only. Every token defaults to a 20-year expiry unless a shorter one is set, which is exactly the kind of setting that sits outside the parts of an organisation anyone reviews day to day.
We test the organisation you actually run: which accounts hold Member versus Admin, whether SSO is actually enforced, the personal, deploy, org and read-only tokens issued from it, the secrets, fly.toml exposure and 6PN networking your apps use, and the access boundary on any Fly Volumes or Managed Postgres cluster attached to them. We never test Fly.io’s own infrastructure, in the same way we test client configuration on Heroku apps rather than Heroku’s platform.
SCOPE
What we review in a Fly.io organisation
Organisation Roles: Member and Admin
Fly.io organisations run on two roles: a Member can already create and destroy apps, deploy new versions, manage secrets, volumes and Machines, and reach the org’s private network, while only an Admin can invite or remove users, view or update billing, and delete the organisation. We test how many accounts hold each role, whether a Member reaches further than that list allows, and whether a removed member’s WireGuard peers, tokens and secrets were actually cleaned up afterwards.
Single Sign-On for Organisations
An organisation can turn on SSO enforcement so members authenticate through Google Workspace or a GitHub organisation as its identity provider, and Fly.io’s own guidance is that you usually should, since it inherits the IdP’s 2FA and passkeys rather than relying on a Fly.io password alone. We test whether SSO is actually enforced for the org, and if it is not, whether every account holding Admin is genuinely protected by strong authentication rather than a password.
Access Tokens and Macaroons
The token printed by fly auth token is a short-lived, all-powerful personal credential created automatically on every login, and Fly.io’s current guidance is to stop using it for CI or third-party services in favour of a macaroon-based token scoped to a single app, a whole org, or read-only access, each with its own name and expiry. We test which token type is wired into every pipeline and integration, how many still carry the default 20-year expiry, and whether an old or unused token is still valid.
Secrets and the Encrypted Vault
A value set with fly secrets set is encrypted into a per-app vault that Fly.io’s API servers can only encrypt into, never decrypt out of, and it reaches your app only as a plain environment variable injected into each Machine at boot. We test which secrets are still readable from inside a running Machine, whether a staged fly secrets set –stage change left an old value live on Machines that haven’t restarted yet, and whether a deploy log has ever printed one.
fly.toml Environment Variables and Precedence
The optional [env] section in fly.toml sets plain, non-sensitive environment variables as strings, cannot use a name starting with FLY_, and is silently overridden by a secret of the same name, or by the PRIMARY_REGION variable when primary_region is set elsewhere in the file. We test what a committed fly.toml actually reveals in its [env] block, and whether a value that should have been set with fly secrets set is sitting in plain sight instead.
Public Exposure via http_service and [[services]]
An app’s [http_service] block in fly.toml is what puts it on the internet: it listens on ports 80 and 443 by default, proxies to whichever internal_port your app binds, and can force HTTPS, while any other port needs its own [[services]] entry to be reachable at all. We test which ports and services a fly.toml actually exposes to the public internet against what the app genuinely needs, and whether an internal-only process was ever given a public port by mistake.
Private Networking: the 6PN WireGuard Mesh
Every app in an organisation is joined to a 6PN, a mesh of WireGuard tunnels over IPv6 that lets apps in the same org reach each other by .internal DNS name automatically, while Fly.io will not forward traffic between two different organisations’ 6PNs unless you explicitly allow it. We test what is actually reachable over the 6PN between your apps, whether a service that should be isolated in its own private network is still joined to the shared one, and what a compromised app on that mesh could reach from there.
Multi-Region Deployment and Regional Exposure
Fly.io deploys Machines and volumes into whichever regions you choose, only some of which run a WireGuard gateway for private network access, and every Machine learns its own region at boot through the FLY_REGION environment variable. We test whether a region was added for capacity or latency and never revisited, whether a service is reachable in a region it was never meant to run in, and whether region-scoped .internal DNS queries reveal more about your deployment than they should.
Fly Volumes: Persistent Storage Access Boundary
A Fly Volume is a slice of a single physical server’s NVMe drive that belongs to one app, exists in one region, and can only ever attach to one Machine at a time, and it is encrypted at rest by default unless a volume was explicitly created with –no-encryption. We test which volumes are still unencrypted, whether an old, unattached volume from a decommissioned Machine still holds data nobody accounts for, and how daily snapshot retention is actually configured against your recovery needs.
Fly Managed Postgres: Roles and Network Access
A Managed Postgres cluster is not reachable over the public internet at all; it lives inside your organisation’s 6PN and is only reached through a pooled or direct connection string, flyctl’s mpg proxy, or a WireGuard connection, while each database user is created with one of three roles: schema_admin, writer or reader. We test which role every database user actually holds against what their application needs, and whether the direct connection string, meant for migrations and advisory locks, is being used more broadly than that.
OUR PROCESS
Fly.io Deployment Security Review: From Scope to Attestation
Scope and Access
We agree which Fly.io organisation, apps, Managed Postgres clusters and regions are in scope, plus a login with each role in use.
Configuration and Role Mapping
We map every organisation role, access token and Managed Postgres user against what it actually grants, alongside your current fly.toml exposure and 6PN configuration.
Manual Testing
A CREST-certified tester manually tests service exposure, secrets handling, private networking boundaries and token scope, chaining findings where they compound.
Attestation and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Fly.io pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Fly.io Deployment Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 4 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote4 to 6 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Fly.io For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Fly.io Deployment Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Fly.io organisation?
We need a login with the Member or Admin role in use, ideally Admin for full visibility of billing and access history, plus visibility of your current fly.toml files, access tokens and organisation roles. An org-scoped token created with fly tokens create org speeds up several checks but is not required to start.
Will testing touch our live data?
Testing focuses on organisation roles, tokens, secrets configuration, fly.toml exposure, private networking and Managed Postgres access controls rather than the contents of your databases or volumes. Where proving a finding needs a test record, we agree the exact scope with you first and remove anything we create once testing is complete.
Is this hosted on our infrastructure or Fly.io’s?
Your apps, Machines, volumes and Managed Postgres clusters all run on Fly.io’s infrastructure, so there is nothing separate for you to host. The review is scoped to the organisation configuration you control: roles, tokens, secrets, fly.toml and network exposure, not to Fly.io’s own platform.
How long does a Fly.io security review take?
A single organisation with a typical number of apps, one Managed Postgres cluster and a handful of volumes sits in our 2-day single-org scope, with a report usually landing around 5 working days after kickoff. An organisation running several regions, multiple Postgres clusters or a large number of apps extends that scope.
What is out of scope for a single-org review?
Testing Fly.io’s own infrastructure, hypervisor or shared platform is never in scope, and we do not run denial-of-service testing against any Fly.io app. The application code running inside your Docker image or Fly Machine is scoped and quoted separately from the organisation and configuration review.
Does Fly.io have a customer penetration-testing policy we need to follow?
Fly.io publishes its security practices and a vulnerability remediation timetable for issues in its own platform, reported to security@fly.io, but it does not publish a separate policy setting out notification steps or rules of engagement for a customer testing their own organisation. We confirm Fly.io’s current terms and any organisation-specific conditions during scoping before testing begins.
Do you need our source code or standing admin access?
No. We test with the role-based access and tokens you provide, and we do not need standing Admin access beyond what is needed to verify a specific finding during the engagement. Source code for anything you deploy on Fly.io is only needed if you commission the application itself as a separate assessment.
Are your testers CREST certified?
Yes. Every Fly.io engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Fly.io organisation
A Fly.io organisation has only two roles, and Member already reaches every app’s secrets, volumes and Machines. We test the roles, tokens and network exposure your team actually configured, not Fly.io’s platform. CREST-certified testers, fixed price from £2,320 for a 2-day single-org scope, quoted within 24 hours.



