Security
Dedicated instance per customer, separate encryption keys, EU hosting options — isolation that is true today.
Isolation is the product
Envoy is not a shared multi-tenant app with row-level tenancy. Each customer gets their own instance.
What is true today
- Dedicated instance per customer — separate containers, ports, and hostname (
<slug>.clonepartner.com). - Separate encryption key per tenant — generated at provision time; the portal never holds tenant API keys or cell SSH credentials.
- Fleet / portal security boundary — infrastructure secrets stay on the private fleet; the public portal talks over a service-token internal API only.
- EU hosting options — cells can be placed in EU regions; ask us for the region that matches your DPA.
- No shared customer database — your data is not co-mingled with other tenants’ tables.
What we do not claim yet
We will not invent certifications, SOC reports, or “zero-trust mesh” language that is not shipped. When those land, this page will say so.
Account deletion
You can delete your account from the portal. That destroys the fleet tenant and anonymises personal fields while retaining Stripe billing records we are required to keep.