We’re doing a security review before moving a workload with regulated personal data to Fly. The docs say API servers “can only encrypt; they cannot decrypt secret values” and that host agents decrypt app secrets at machine boot; we also saw the June Petsem emergency maintenance.
- Which Fly roles/personnel can operate or invoke the host-agent decryption path for customer app secrets (directly or via tooling), and under what controls (approvals, audit logging)?
- Are app-secret plaintexts ever accessible outside a customer’s machine boot path (Petsem ops, debugging, incident response)?
- Is operator access to that path logged, and is it in scope of the SOC 2 audit?