Skip to Content

Security

Practical controls without sensitive operational detail.

Elroi publishes the protections customers need to understand while keeping exact infrastructure, credentials, and internal operating details private.

Shared responsibility

Security depends on both Elroi-managed controls and customer decisions about lawful data, users, roles, and process approvals.

Control areas

Concrete enough to evaluate, careful enough to stay safe.

Tenant isolation

Each unrelated customer is designed for separated runtime, database role, filestore, secret set, backup scope, route, release assignment, and resource policy.

Access control

Staff permissions are role-based. High-risk operations require reason capture and independent approval before action.

Audit evidence

Privileged changes and exported audit evidence are append-only, reviewed, and retained for investigation.

Release safety

Package and module changes pass compatibility checks before reaching tenant operations.

Backup discipline

Backup frequency, retention, and restore rehearsal expectations are documented by package and operating runbook.

Incident handling

Security concerns are triaged, assigned, communicated, and followed through according to severity.