Shared responsibility¶
This section describes how Drovio is built and operated. Who operates it depends on the edition. On the Cloud edition we run the service and everything under it. On the Enterprise edition you run it, and securing the deployment becomes a joint effort: we provide the software, the defaults and the instructions, you own the infrastructure it runs on.
Who does what¶
| Area | Cloud (SaaS) | Enterprise (on-premises) |
|---|---|---|
| Infrastructure | Drovio, on AWS | You |
| Operating system, patching, hardening | Drovio | You, see Requirements |
| Installing and updating Drovio Server | Drovio | You, see Installation and Docker deployment |
| TLS certificate and HTTPS | Drovio | You, see Enable HTTPS |
| Database, backups and restore | Drovio, on encrypted RDS | You, see Requirements and High Availability |
| Network exposure and firewall rules | Drovio | You, see Protocols & ports |
| TURN relays | Drovio, deployed worldwide | You, optional, see Relay server (TURN) |
| Identity provider and SSO | Drovio, SAML | You, see SSO (SAML & OIDC) |
| Accounts and license allocation | Shared | You, see Licensing & users |
| Statistics retention and anonymization | Drovio, daily | You, see the anonymize settings |
| Logs and their retention | Drovio, one year | You |
| Responding to an incident on the deployment | Drovio | You, with our support |
| End-user machines and the Drovio app | You | You |
What remains ours in both cases¶
The security of the software itself never moves: the cryptography described in Architecture & data flow, the way sessions are protected in Session access & control, the way passwords are stored, and fixing vulnerabilities within the targets set in Vulnerability handling. Whichever edition you run, report anything you find to security@drovio.com.
What never reaches us on Enterprise¶
Running Drovio yourself is not only a matter of hosting. No personal data is collected by or transmitted to Drovio, no sub-processor is involved, and there is no transfer of data outside your own infrastructure. See Compliance & data processing.