Security
Erlangly is self-hosted: it runs on your server, so your data never passes through ours.
How it's built
- A new install is set up through a secret one-time link, so nobody else can claim it.
- Passwords are hashed with bcrypt and need at least 12 characters. Sessions last 30 days.
- API tokens are stored only as digests and shown once. Each acts with its owner's role.
- The mail server password is encrypted at rest and kept out of the audit trail.
- Every change to people, schedules and settings is in an append-only audit trail.
- A strict Content-Security-Policy, and HTTPS with a Let's Encrypt certificate when you give it a domain.
- The container runs as an unprivileged user. Nightly backups stay on your server; copies elsewhere are up to you.
- No telemetry. The only outside call is a daily update check, which you can turn off.
Reporting a problem
If you find a security problem, please email security@erlangly.com with what you found and how to reproduce it. We'll reply within two business days, keep you posted while we fix it, and credit you if you'd like. Please don't test against installs that aren't yours.