Operate

Built so security stops saying no.

Multi-tenant isolation, roles that match your org chart, SSO and SCIM, PII masking, encryption with your keys, residency and audit.

PLATFORM · edverix staff · separate schemaORG · org_c044PROJECT · theirsRowsisolated by org idORGANISATION · Acme Retail · org_8f21PROJECT · StagingedvS7Q2LM0BDAPI keys2 · scopedUsers14 · rolesPROJECT · ProductionedvK3P9QW2AXAPI keys2 · scopedUsers14 · rolesREQUEST PATHRequestkey · sessionAuthenticationapi key · sessionRolespermission checkTenant scopeorg + projectProject rowsscoped query403 · org_c044 is not yours
SSO / SAMLSCIM2FAIP allow-listPII maskingBYOK encryptionaudit log

regionsIN · SG · EU · US · self-hosted

Platform staff and customer organisations are separated at the schema level. Every row carries its organisation and project, and every query is scoped by them, so a request for another tenant's data is refused, not silently filtered. Enterprise controls unlock when a deal needs them.

Overview

Edverix separates platform staff from customer organisations at the schema level, scopes every query by tenant and project, and records every administrative action. Enterprise controls are unlocked when a deal needs them: SAML, SCIM, object-level access, PII tokenisation, bring-your-own-key encryption and dedicated data planes.

Only on Edverix

  • KYC-backed onboardingOnly on Edverix

    Organisations are verified before activation, with jurisdiction-specific document requirements.

Capabilities

Everything in Security

12 capabilities in 3 groups, organised the way the product is.

Access

Enterprise sign-in

SAML single sign-on, SCIM provisioning, two-factor authentication and IP allow-listing at account and user level.

Roles that match your org chart

Built-in and custom roles, with separate permissions for building a campaign and approving it.

Object-level access control

Partition users, events, segments and campaigns by attribute so a regional team sees only its region.

Service accounts with key rotation

Primary and secondary keys for zero-downtime rotation, with scopes.

Data protection

Tenant and project isolation

Every row carries organisation and project; a request for another tenant's data is refused, not silently filtered.

PII masking and tokenisation

Sensitive fields stored masked, unmasked only for a specific permission, with a token vault where needed.

Encryption with your own keys

Field-level encryption at rest with keys held in your key-management service.

Data residency

Choose the region your data lives in, or run the whole platform in your own cloud.

Governance

Audit log

Every administrative action with actor, target and before-and-after state, exportable to your SIEM.

KYC-backed onboardingOnly on Edverix

Organisations are verified before activation, with jurisdiction-specific document requirements.

Usage metering

Events, messages and storage metered per project, visible to you in real time.

Erasure and retention

Data-subject erasure end to end, and retention policies per event type.

FAQ

Questions about Security

Where is data hosted?

In the region you choose at onboarding. Regulated customers can run Edverix inside their own cloud account with the same feature set.

How are API keys protected?

Keys are shown once at creation and stored only as a peppered hash. Keys embedded in client apps can only write events; any management call with an SDK key is refused.

Get started

See Security on your own data.

Send your first event in an hour, simulate your first journey against real history, and keep every byte of it in a database you can query.

  • No credit card for the Developer plan
  • Bring your own providers
  • Export everything, any time