Security
Elpis handles credentials, incident data and AI-driven remediation proposals. Here is exactly how that is protected, without marketing gloss.
1. Accounts and sessions
- Passwords are hashed with pbkdf2-sha256 (100,000 iterations) with a per-user salt and constant-time comparison. Plain passwords are never stored.
- Sessions use short-lived access tokens (30 minutes) with rotating refresh tokens (7 days). Logging out clears the tokens from your browser.
- Four roles gate every action: viewer, engineer, sre and admin. Read and write permissions are enforced on the server, not just hidden in the interface.
2. Data isolation
Every incident row carries its owner. Reads are scoped so an account only sees its own incidents plus intentionally shared demo data, and writes require authentication plus an ownership check. The shared demo accounts (viewer, engineer, sre, admin) are public by design, so keep private work in your own account. Isolation is covered by automated tests in our suite.
3. Your BYOK keys
- LLM keys and GitHub tokens are encrypted at rest with AES-256-GCM using a server-side key that never ships in the repository.
- The API is write-only for secrets: once saved, keys are never returned or echoed. The interface only shows whether a key exists.
- Keys are used only to call the provider endpoints you configured. Revoke a key at your provider any time and Elpis loses the ability to use it.
4. AI safety rails
- Remediation never executes automatically. A human with the right role must approve every proposal, and critical-severity actions are blocked outright.
- Investigations run under hard limits: tool-call caps, per-incident budget caps, timeouts and retry limits, so a bad run cannot run away.
- Every proposal carries its evidence and risk classification, and every action is recorded in an audit trail you can review.
5. Transport and infrastructure
- All traffic is served over HTTPS through our edge provider.
- Database connections are encrypted end to end; data at rest is encrypted by our managed Postgres provider.
- Production access is limited to the operator running the service. Current subprocessors are listed on the Subprocessors page.
6. Responsible disclosure
If you find a vulnerability, email notsekiro11@gmail.com with the steps to reproduce and the impact. We will acknowledge it, work on a fix and keep you updated. We do not run a paid bounty programme yet, and we will not take legal action against good-faith reports that avoid privacy violations, data destruction and service disruption.
See also: Privacy Policy · DPA