Is Heroku safe?
Review Heroku security risks.

Nudge Security provides security profiles for thousands of SaaS apps, including Heroku. This public profile has the basics you’ll need for a vendor risk assessment. For more details on Heroku, including breach history, start a free trial of Nudge Security.
Heroku Security Profile

CATEGORY

Developer Tools

Organization Details

What is

Heroku

?

Heroku is a platform as a service (PaaS) that enables developers to build, run, and operate applications entirely in the cloud.

HEADQUARTERS

HOSTING

HOSTING LOCATION

Who's Using Heroku in your org?

Nudge Security discovers every user for every SaaS app within minutes of starting a free trial. No credit card required.

Learn how

Security Program

SECURITY CERTIFICATIONS

SOC2 Compliance
PCI Compliant
HIPAA Compliant
SOC2 Compliance
SOC 2 Compliant
GDPR Compliant
ISO 27001 Compliant
FedRamp Compliant
CSA Star Level 1
Compliant

SECURITY PAGE

SECURITY PORTAL

BUG BOUNTY

VULNERABILITY DISCLOSURE

PRIVACY POLICY

STATUS PAGE

Heroku breach history
Has Heroku experienced a recent breach? Start a free trial of Nudge Security for a full breach history and more security program details.
Learn more

Authentication

AUTHENTICATION / SSO

Supported Okta Features
  • SAML
Login with Google support
Login with Microsoft support
Supports SSO
Two-factor authentication via SMS
Two-factor authentication via E-mail
Two-factor authentication via Hardware
Two-factor authentication via Software
Two-factor authentication via TOTP
Two-factor authentication via U2F

oauth details

Heroku OAuth Grants
Is Heroku connected to your other business apps? Start a free trial of Nudge Security to see all app-to-app OAuth grants.
Learn more

Supply Chain

Apps in Heroku's supply chain
  • Heroku
  • SendGrid
  • Amazon Web Services (AWS)
  • Pardot
  • Fastly
  • Proofpoint
  • Mailgun
  • Google Workspace
  • Salesforce.com
  • OneTrust
  • Google Tag Manager
  • Google Analytics
  • GlobalSign
Heroku supply chain breach history
What's in Heroku's SaaS supply chain? Start a free trial of Nudge Security to manage software supply chain security at scale.
Learn more

Subdomains

Heroku subdomains
  • data-staging-private.heroku.com
  • api-starter.postgres.heroku.com
  • get.heroku.com
  • odata-us.heroku.com
  • postgres-api.heroku.com
  • connect-4-virginia.heroku.com
  • docs.heroku.com
  • connect-2-dublin.heroku.com
  • odata-4-virginia.heroku.com
  • kafka-api.heroku.com
  • kb.heroku.com
  • www-staging.heroku.com
  • odata-sydney.heroku.com
  • status-api-staging.heroku.com
  • help.heroku.com
  • registry.heroku.com
  • sydney.ingress.logs.heroku.com
  • app.metrics.heroku.com
  • virginia.ingress.logs.heroku.com
  • cassandra-api.heroku.com
  • exec-manager.heroku.com
  • events.heroku.com
  • auth.heroku.com
  • www.heroku.com
  • connect-sydney.heroku.com
  • connect-frankfurt.heroku.com
  • cli.heroku.com
  • connect-oregon.heroku.com
  • m.heroku.com
  • tokyo.ingress.logs.heroku.com
  • discussion.heroku.com
  • odata-tokyo.heroku.com
  • connect-3-virginia.heroku.com
  • id.heroku.com
  • connect-dublin.heroku.com
  • about.heroku.com
  • odata-frankfurt.heroku.com
  • sso.heroku.com
  • engineering.heroku.com
  • api.heroku.com
  • api.postgres.heroku.com
  • redis-api.heroku.com
  • odata-2-virginia.heroku.com
  • buildpack-registry.heroku.com
  • signup.heroku.com
  • odata-3-virginia.heroku.com
  • legal.heroku.com
  • connect-us.heroku.com
  • brand.heroku.com
  • backboard.heroku.com
  • www0.assets.heroku.com
  • platform-virginia.ingress.logs.heroku.com
  • build-output.heroku.com
  • release-output.heroku.com
  • dataclips-cname-test.heroku.com
  • devcenter-next.heroku.com
  • policy.heroku.com
  • news.heroku.com
  • devcenter.heroku.com
  • changelog.heroku.com
  • chatops.heroku.com
  • status.heroku.com
  • art.heroku.com
  • beta.heroku.com
  • assets.heroku.com
  • business.heroku.com
  • va-acm.heroku.com
  • cli-analytics.heroku.com
  • support.heroku.com
  • yobuko.heroku.com
  • cli-auth.heroku.com
  • trust.heroku.com
  • success.heroku.com
  • oregon.sessions.logs.heroku.com
  • odata-connect-eu.heroku.com
  • vault.heroku.com
  • blog.heroku.com
  • waza.heroku.com
  • app-setup-api.heroku.com
  • functions-identity.heroku.com
  • jobs.heroku.com
  • odata-connect.heroku.com
  • repositories.heroku.com
  • confirmation.heroku.com
  • pricing.heroku.com
  • signup-private-staging.heroku.com
  • python.heroku.com
  • frankfurt.sessions.logs.heroku.com
  • flask.heroku.com
  • sydney.sessions.logs.heroku.com
  • addons-sso.heroku.com
  • kolkrabbi.heroku.com
  • help-assets.heroku.com
  • go.heroku.com
  • api.metrics.heroku.com
  • cli-assets.heroku.com
  • enterprise.heroku.com
  • dashboard.heroku.com
  • test-output.heroku.com
  • partners.heroku.com
  • shogun-cassandra.heroku.com

Regain control of SaaS security.

Nudge Security discovers all SaaS accounts ever created by anyone in your org within minutes of starting a free trial. Get a full SaaS inventory today, along with insights and automation to improve your SaaS security posture.