Trust
Security at EternaEdge
We build for organizations whose work invites targeting. Security is a design constraint here, not a feature list: it shapes how the platform is engineered — governed access, isolation that fails closed, a record of every consequential action — and it shapes this page. What is built is stated as built. What is planned is stated as roadmap.
Architecture
Isolated by design.
The platform is one governed system — one platform foundation, five product pillars, one assistant layer — and isolation between customers is a property of its data layer, not a policy document.
Edge-delivered infrastructure
Products are delivered from Cloudflare’s global edge network. Traffic is encrypted in transit, and the serverless runtime leaves no long-lived servers to patch or forget. The provider maintains the infrastructure layer continuously; we concentrate our attention on the application layer, where your data lives.
Isolation that fails closed
Every query in the data layer carries the caller’s organization scope, and the scoping is designed to fail closed: a caller whose organization cannot be resolved sees nothing — not everything. We audit read, write, and delete paths for cross-tenant access as part of ongoing security review, and treat each finding as a defect to fix, not a note to file.
Dedicated instances
For programs that require structural separation, a dedicated instance with its own database is available for qualified deployments — isolation by infrastructure, not by query predicate alone.
Access
Authentication and access control.
What is built today, and what is on the roadmap — kept separate on purpose.
Security work lands first in PATHWAY — Travel Security, our most operationally mature product. The controls below describe what is built there today; a shared platform identity layer is designed to carry the same controls to every pillar, and sits on the roadmap beside the items that follow it.
- Password security
- Passwords are stored as salted PBKDF2-SHA256 hashes — never in plain text, never in a reversible form.
- Login protection
- Failed sign-in attempts are tracked, and repeated failures lock the account. Sessions expire, and the timeout is configurable by the customer organization.
- Role-based access
- Every request is authorized on the server against the user’s role and position in the organization’s hierarchy. Travelers see their own records, administrators see their organization, and no role sees past its scope.
- Multi-factor authentication
- TOTP-based multi-factor authentication is in development, targeted for Q4 2026.
- Single sign-on
- SAML and OIDC single sign-on through established identity providers is targeted for the first half of 2027, with SCIM provisioning to follow.
We list these as roadmap because they are not shipped. When they ship, this page will say so.
Auditability
Recorded, attributed, reviewable.
Defensible action needs a record. The platform writes one as it works.
Layered audit logging
Authentication events, administrative changes, and record-level activity are written to audit logs as they happen. Each entry carries the actor, the action, the record it touched, and the request origin — so a reviewer can reconstruct who did what, when, and from where.
Labeled provenance
Intelligence content states its source. Travel advisories in PATHWAYcome from the U.S. Department of State’s public advisory feed, cached with publication dates and linked to the originals. When a source is unavailable, the product says so — it does not fill the gap. Demonstration data is labeled as synthetic wherever it appears.
AI assistants operate within APEX, using governed, auditable data. They do not bypass authority, workflows, or oversight.
AI FORCE — Assistants is in development, and we describe it as roadmap until it ships. Assistants are designed to draft and propose; your people review, approve, and act — and every assistant action is designed to land in the same audit stream as human action.
Compliance
Alignment, stated plainly.
We hold compliance claims to the same standard as product claims: alignment is not certification, and we say which one we mean.
- ISO 31030
- PATHWAY supports ISO 31030 travel risk management compliance programs. Supports — we do not claim certification.
- NISPOM · CMMC
- Our practices are NISPOM- and CMMC-aligned. Aligned — we do not claim certification, accreditation, or clearance.
- SOC 2
- A SOC 2 examination is on our roadmap. Until we hold a report, we do not claim one — here or anywhere else.
- Classified information
- EternaEdge systems do not process classified information. Classification labels inside the platform are platform access controls — never national-security classification.
Disclosure
Report a vulnerability.
Security research makes the platform stronger. We want to hear what you found.
If you believe you have found a vulnerability in an EternaEdge product or this website, write to contact@eternaedge.com. Tell us the product, the steps to reproduce, and what you observed. We read every report, respond to the reporter, and fix verified issues. We ask for reasonable time to remediate before any public disclosure. We do not operate a paid bounty program.
Put your review team in front of us.
Security questionnaires, procurement diligence, architecture review — bring them. We answer with what is built today and what is on the roadmap, and we keep the two separate.