Your frames, in a vault you can see into.
One server in Sydney, verified people only, a named decision on every record, and deletion whenever you ask. The software organises and suggests; your team decides what is released.
MyElysium does not hold SOC 2, ISO 27001 or IRAP certification. Here is every control we run, where it lives, and what we do not yet have.
The threats a camera-trap dataset faces today, and what happens here
- Loss of the frames. Frames, records and exports live on named Docker volumes on one server in Sydney; a backup script and a written rollback runbook exist. Not yet: an off-host backup copy and a rehearsed restore.
- Credential theft. Email confirmed before sign-in; sign-in rate-limited per client address; passwords salted and hashed, reviewer credentials peppered, session tokens hashed. Not yet: multi-factor authentication.
- Supply chain. Secret scanning and a dependency audit on every push; backend and frontend test suites before an image is built; non-root container with memory and process limits. Not yet: base images pinned by digest.
- Sovereignty and offshore transfer. Frames stay in Sydney, Australia. Transactional email is relayed through Resend in Tokyo and carries names and addresses, never frames. Crowd review is off in production.
- AI misuse of your data. No training on your imagery without written opt-in. Every released record carries its provenance; a model suggestion is never released as verified.
- Insider and access. Reviewer access scoped per tenant; sensitive-species coordinates withheld unless authorised in writing; deletion on demand with a surviving audit line. Not yet: a scheduled retention purge.
Controls ledger
Every control, where it lives in code or configuration, and whether it is built in or not yet. Checked 14 September 2026. The same rows with evidence paths are kept in docs/security/CONTROLS_LEDGER_2026-09-14.md.
Rights in a MyElysium data package · Talk through your data rules · Privacy