Data processing controls
This page describes the technical data-processing controls implemented in Eresus Guard. A contractual Data Processing Addendum is provided for procurement and countersignature with the applicable customer agreement.
Authorized processing boundary
Customer-authorized targets, source, findings, and assessment evidence are handled in the project and tenant context that owns the work. The product is designed for authorized security testing; it does not grant authority to scan systems or process data outside that approved boundary.
Tenant, identity, and secret controls
- Tenant-scoped records and service paths are bound to an explicit tenant identity.
- Role policies are enforced for tenant administration and project access. Enterprise packages add OIDC and SAML single sign-on.
- Sensitive OIDC, SAML, and integration secret material supports authenticated envelope encryption through the configured key-custody backend.
- Tenant API keys are stored as hashes and support scoped, expiring access.
Audit and evidence integrity
Security-relevant administrative actions are recorded as append-only audit events. Audit rows are chained with verifiable hashes, and finding evidence is not hard-deleted through ordinary finding operations.
Erasure and legal holds
The governance workflow supports a tenant erasure request that is rejected while an active legal hold exists. A completed erasure records an auditable completion event and certificate; backup rotation and contract-specific retention commitments are addressed in the applicable customer agreement.
Procurement documentation
For a countersigned DPA, current subprocessor information, data-residency details, retention commitments, transfer terms, or incident-notification terms, contact contact@eresussec.com. Those commitments are provided in the agreement package for the customer and deployment concerned.
Questions about this document?
Email contact@eresussec.com.