Skip to content

Shared responsibility

This section describes how Drovio is built and operated. Who operates it depends on the edition. On the Cloud edition we run the service and everything under it. On the Enterprise edition you run it, and securing the deployment becomes a joint effort: we provide the software, the defaults and the instructions, you own the infrastructure it runs on.

Who does what

Area Cloud (SaaS) Enterprise (on-premises)
Infrastructure Drovio, on AWS You
Operating system, patching, hardening Drovio You, see Requirements
Installing and updating Drovio Server Drovio You, see Installation and Docker deployment
TLS certificate and HTTPS Drovio You, see Enable HTTPS
Database, backups and restore Drovio, on encrypted RDS You, see Requirements and High Availability
Network exposure and firewall rules Drovio You, see Protocols & ports
TURN relays Drovio, deployed worldwide You, optional, see Relay server (TURN)
Identity provider and SSO Drovio, SAML You, see SSO (SAML & OIDC)
Accounts and license allocation Shared You, see Licensing & users
Statistics retention and anonymization Drovio, daily You, see the anonymize settings
Logs and their retention Drovio, one year You
Responding to an incident on the deployment Drovio You, with our support
End-user machines and the Drovio app You You

What remains ours in both cases

The security of the software itself never moves: the cryptography described in Architecture & data flow, the way sessions are protected in Session access & control, the way passwords are stored, and fixing vulnerabilities within the targets set in Vulnerability handling. Whichever edition you run, report anything you find to security@drovio.com.

What never reaches us on Enterprise

Running Drovio yourself is not only a matter of hosting. No personal data is collected by or transmitted to Drovio, no sub-processor is involved, and there is no transfer of data outside your own infrastructure. See Compliance & data processing.