Security & compliance

Where your data lives, and who can see it.

Both are decisions we make with you before onboarding starts, not defaults you discover afterward. This page states them plainly so your security review has something concrete to work from.

Data residency

Self-hosted today. A managed cloud option is next.

Envera is a single portable container running against a read-only database connection — the same architecture whether it sits in your infrastructure or in a cloud we operate for you. What's real today is on the left below; the right is where deployment is heading.

ROADMAP — a self-service, pick-your-region hosted offering is not built yet. Today, hosting is either fully in your hands (see on-premise) or arranged directly with us on a case-by-case basis.
On-premise / private cloud

Inside your own infrastructure — available now

Envera runs as a container against a read-only database connection, so it fits inside a security boundary you already operate — no exception has to be written for it. TLS is handled by an included reverse proxy that obtains and renews its own certificate automatically.

  • Your data centre, or your private cloud tenancy
  • No data ever leaves your network boundary
  • Deploy tooling is written to avoid disturbing other services already running on a shared host
Hosted by Envera

A managed instance — roadmap

The same container, operated for you instead of by you. Arranged directly during onboarding today; a self-service region picker is the next step, not a shipped feature.

  • Available on request, any plan
  • TLS in transit, encrypted storage at rest
  • Self-service region choice: planned, not yet built

Neither option changes what the application does with your data — see access control and migration for that.

Access control

Not everyone who can see a number should be able to change one.

Today, Envera authenticates with a single shared credential for the whole deployment — see the architecture below for what already protects that one password. Separating who can look at figures from who can touch the configuration behind them is the next milestone, not a shipped feature yet.

ROADMAP — the three levels below describe the shape access control will take, not what ships today. If per-user roles are a hard requirement for your rollout, say so on the first call — it changes the sequencing, not whether we build it.
ADMIN

Manages sites, users and roles, conversion factors, and the methodology configuration. Typically one or two people per organisation.

ANALYST

Full read access across every module, plus export. Cannot change methodology, factors, or user permissions.

VIEWER / AUDITOR

Read-only, optionally scoped to specific sites. Built for the reviewer who needs to verify a figure, not administer the system.

The plan is for roles to reach every plan, including Site. Even a single facility would benefit from separating the person who calibrates a conversion factor from the manager who just needs the monthly number — access control shouldn't be something you have to upgrade into. That's the target; it isn't built yet.

Architecture

The parts of the design that exist so nothing else has to change.

Read-only by construction

The application holds a read-only database credential. It cannot write back into your system of record even if instructed to — there is no write path to remove.

No credentials in client code

Sessions are signed and expire; nothing capable of reaching your data ever ships to a browser. A compromised laptop is not a compromised database.

TLS everywhere

Every deployment sits behind TLS, cloud or on-premise. Data in transit is encrypted the same way regardless of which residency option you chose.

Fails closed

If access controls are misconfigured or credentials are missing, the application serves nothing rather than serving data to whoever asks. Nothing is exposed by default.

One password change revokes every session

The session-signing key is derived from the shared credential itself, not a separate secret. Rotate the password and every outstanding session, on every device, is invalidated at once — with nothing extra to configure.

Your data, exportable, always

Full-precision CSV export exists for a reason beyond convenience: nothing you put into Envera is held hostage inside it.

Certifications

Where we are, honestly.

Formal third-party certifications (SOC 2, ISO 27001) are not yet in place. What is described on this page is the architecture those audits would examine — we would rather state that plainly than imply a certification we do not hold.

If a certification is a hard requirement for your procurement process, tell us during the first call — it changes the shape of the engagement, not whether we can have it.

Procurement

We complete vendor security questionnaires directly.

Send us yours and we will fill it out against the architecture on this page — no generic template, no marketing language standing in for an answer we do not have.