Security by Design
for Critical Operations.
EdgePortal runs as a dedicated instance for every customer – on request as an appliance in your own data center – and follows a defense-in-depth approach across hardware, operating system, platform, and application. In the on-premise model, your data stays entirely on your premises.
Protection at Every Layer
EdgePortal combines several layers of protection, from disk encryption to a documented incident-response process. Here are the most important ones:
Privacy by Default
We only collect the data that is actually required for operations. In on-premise deployments, all customer data remains exclusively in your data center, with no cloud and no third-country transfer. All processing is GDPR-compliant.
Encryption
All connections are secured with TLS 1.2/1.3, HSTS, and forward secrecy. Our HTTPS configuration earns an A+ rating from SSL Labs. The appliance uses full-disk encryption with hardware-backed keys (TPM 2.0) and measured boot, so your data is encrypted both in transit and at rest.
Application Security
EdgePortal protects against the most common vulnerability classes with a proven, security-aware web framework for database access, authentication, and session handling. On top of that, a hardened operating system with a default-deny firewall, automated dependency scanning, controlled updates, and rate limiting protect both API and interface.
Automated Backups
Encrypted backups, including dedicated database dumps, run automatically. EdgeOps takes care of operation and restore, and mirrored drives (RAID 1) add redundancy.
Monitoring
Critical operating states are continuously monitored and trigger alerts. EdgeOps operates the central logging and SIEM analysis, keeping events traceable. If an incident does occur, a documented incident-response process defines analysis and communication.
Authentication
Optional two-factor authentication via TOTP, enforceable tenant-wide by administrators. Passwords are stored exclusively as Argon2 hashes, and we strictly filter all keys from our logs. Every tenant receives dedicated API keys, and a strict multi-tenancy model rigorously separates data and permissions.
Infrastructure as Code
Our systems are managed entirely as infrastructure as code, so every system is built identically. Every change we make to a system is tracked in version control, and its execution is logged.
Secure Administrative Access
EdgeOps only logs into systems with personalized, secure two-factor tokens. Deployments use smartcard-based SSH keys.
And Much More
We don't publicly describe every protection we have in place. Some measures work best when they are not documented in detail. If you would like a deeper look, we are happy to provide one as part of an audit.

Security your customers can see
The login dialog carries your brand while the protection works in the background: optionally enforced two-factor authentication, a strict multi-tenancy model, and dedicated API keys per tenant. Security becomes part of everyday use without slowing your customers down.
A Dedicated Instance for Every Customer
Every customer gets a dedicated instance with no shared infrastructure – as a physically separate appliance in their own data center or as a single-tenant instance operated by EdgeOps. A clearly defined shared-responsibility model sets out who is accountable for what.
EdgeOps is responsible for
- OS patching, hardening, and application updates
- Backup and restore as well as monitoring and alerting
- Analysis and remediation of incidents on the OS and application level
You are responsible for
- Physical security and access control in your own data center
- Perimeter firewall, network connectivity, and local site coordination
- User management, account lifecycle, and organizational approvals
Audits & Transparency
We will always accommodate our customers' audit requests if they are even remotely feasible. Whether you need a completed questionnaire, a document review, or a more in-depth technical assessment: just talk to us. We'll agree on scope and timing together up front.
Research & Responsible Disclosure
We value the work of security researchers. If you discover a vulnerability in EdgePortal or our infrastructure, please report it to us confidentially and allow us reasonable time to remediate before publishing any details. Please do not attempt to harm our users, customer data, or the availability of our systems while looking for vulnerabilities.
We're not large enough to run a formal bug bounty program, but if you find a serious vulnerability in our service, we will find a way to show our gratitude.
All our security contact details are provided PGP-signed and in compliance with RFC 9116:
edgeops.de/.well-known/security.txtQuestions about EdgePortal's security?
Talk to us about your requirements or explore the features in detail.