Security & trust
Built to hold your architecture data safely
This page describes how Eidon is actually built β not a compliance checklist. We'll publish formal certifications here as they're completed (epic #343, Track E).
Role-based access control
Admin, editor and viewer roles on every workspace, with an operator layer for platform administration β never a shared login.
Workspace isolation
Every record is scoped to a workspace at the data layer. Cross-tenant data leakage is a defect, not a configuration option.
Secrets encrypted at rest
Connector credentials, SSO/LDAP configuration and API secrets are encrypted at rest, never stored or logged in plaintext.
Full audit trail
Every change to a governed artifact β decisions, designs, blueprints, approvals β is recorded with who, what and when.
SSO & SCIM
Enterprise plans support single sign-on and SCIM-based user provisioning, so access follows your identity provider.
Self-hosted / air-gapped
Deploy Eidon entirely within your own infrastructure with no outbound dependency on us, using an offline signed license.
Data handling
Your data, on your terms
Export anytime. Every workspace can export its full data at any time β this isn't a support ticket, it's a self-service action available to workspace admins.
You choose where it runs. Run in our multi-tenant cloud, or deploy the same product inside your own network with no data ever leaving your infrastructure.
Retention is configurable. Workspace admins control retention policy for audit history and backups rather than us setting it for you.
Cancel with a grace period. Scheduling a workspace for deletion gives you a 30-day window to change your mind before anything is actually removed β it's never an immediate, unrecoverable action unless you explicitly choose that instead.
Subprocessors
Who else touches your data
On our cloud plans, Stripe processes payments β we never see or store your card details ourselves. That's the only third-party subprocessor bundled with the product today.
Email (trial notices, invitations, notifications) is sent through SMTP credentials you configure yourself in Settings, not a bundled third-party email service β so there's no additional subprocessor there by default.
Optional integrations you connect yourself β Jira, Azure DevOps, Confluence, an SSO/OIDC provider β only exchange data with the destination you configure. We'll keep this list current as our own cloud infrastructure choices (hosting, backups) are finalised, and publish a formal Data Processing Addendum alongside the legal pages once those are ready.