Security depends on both Elroi-managed controls and customer decisions about lawful data, users, roles, and process approvals.
Security
Practical controls without sensitive operational detail.
Elroi publishes the protections customers need to understand while keeping exact infrastructure, credentials, and internal operating details private.
Control areas
Concrete enough to evaluate, careful enough to stay safe.
Tenant isolation
Each unrelated customer is designed for separated runtime, database role, filestore, secret set, backup scope, route, release assignment, and resource policy.
Access control
Staff permissions are role-based. High-risk operations require reason capture and independent approval before action.
Audit evidence
Privileged changes and exported audit evidence are append-only, reviewed, and retained for investigation.
Release safety
Package and module changes pass compatibility checks before reaching tenant operations.
Backup discipline
Backup frequency, retention, and restore rehearsal expectations are documented by package and operating runbook.
Incident handling
Security concerns are triaged, assigned, communicated, and followed through according to severity.