How it works
Multi-tenancy, isolation, and security posture of the hosted environment.
Eddytor Cloud is one shared installation of the same open packages you can self-host, on dedicated Hetzner hardware in Falkenstein, Germany.
The tenancy model
Every request carries a caller scope of (user, organisation, workspace); every
query, storage listing, and engine session is keyed by it.
- Organisations are the tenant boundary: members, roles, API keys, policies, invites, and the audit trail are all organisation-scoped.
- Workspaces subdivide an organisation: shared storage configurations attach to exactly one workspace; a credential bound to workspace A cannot read workspace B's - org Admins must switch workspaces rather than see everything at once.
- Engine sessions are per
(user, organisation, workspace)- DataFusion session, memory budget, and discovered catalog are yours alone. - Row & column security policies load per organisation and are enforced inside the engine on every transport (REST, Flight SQL, MCP).
Compute and the metadata database are shared across tenants; table data is not.
Your data
Eddytor Cloud stores metadata, not table data: organisation and user records, table registrations, policies, and the audit log, all in the EU. Your Delta tables live in the bucket you connect, under your own cloud account and IAM, in your chosen region.
What stays where
| Data | Lives in |
|---|---|
| Your table data (Delta/Parquet files) | Your object store, under your cloud account |
| Table metadata, organisations, users, policies, audit log | Eddytor Cloud's database (Hetzner, Falkenstein - Germany) |
| Storage credentials you register | Eddytor Cloud's database, encrypted at rest (AEAD) |
Self-hosting later needs no export step - point your installation at the same bucket.
Storage credentials are encrypted under an instance-scoped key; delegated (OAuth-linked) access stores no cloud password - each member authenticates as themselves against Azure or Google.
Deleting a user erases the identity and cascades through their personal data; table data is unaffected.
Transport & platform security
- TLS terminates at the ingress gateway with Let's Encrypt certificates; in-cluster traffic runs over mutual TLS.
- The database node has no public address - only a private VLAN.
- Containers run non-root with a read-only root filesystem and all Linux capabilities dropped.
- Sign-in is passwordless (email links or per-organisation SSO/OIDC); the OAuth 2.1 identity provider issues all tokens.
Hosts
| Host | Purpose |
|---|---|
app.eddytor.com | Web UI |
api.eddytor.com | REST API, OAuth, /spec - the canonical API origin |
mcp.eddytor.com | MCP endpoint for AI clients |
flight.eddytor.com | Arrow Flight SQL (gRPC over TLS) |