SECURITY

Security is built into access, administration and delivery.

Private URLs are not treated as protection. Eonturn uses authentication, MFA, role-based permissions, secure sessions, CSRF controls, rate limits, encrypted secrets, audit chains and customer-safe backups.

Owner MFA

Privileged control sessions require an authenticator code or a one-time recovery code.

Role separation

Support, releases, finance, administration and auditing can be separated instead of sharing one unrestricted login.

Short privileged sessions

Eonturn Control uses shorter absolute and idle session limits than normal customer accounts.

Protected releases

Installers are stored outside the public web root, validated, hashed and published separately from upload.

Customer preservation

Schema migrations, atomic database writes and rollback backups reduce the chance of losing customer records during updates.

Tamper-evident audit

High-risk actions are recorded in a linked HMAC audit chain that can be verified from Eonturn Control or the command line.