Skip to content

Demonstrable security

Protection, accountability, evidence.

Security is not a statement. It is a set of controls, records and verifiable decisions that must work every day.

The EudorIA approach Prevent. Detect. Respond. Improve.

Every service keeps information access, customer data and contracted operational activities separate.

01

Protected access

MFA on the portals that handle customer data, secure sessions, separate roles and the principle of least privilege.

02

Segregated services

Internal systems, customer portals, analysis tools and source collection operate in separate environments with controlled network flows.

03

Verifiable trails

Application events, access and administrative activities flow into centralized monitoring and produce evidence.

04

Minimized data

Path does not retain the original configurations; the required results are encrypted. Subscribing to Cyber Intelligence does not activate scans or monitoring of your infrastructure.

05

Application protection

Connection encryption, application protections, abuse limits and updates reduce the exposure of public services.

06

Incident management

Detection, classification, escalation, communication and improvement are handled as a single process.

Automated access

Crawlers and bots require prior authorization.

Crawling, scraping and automated scans are not authorized by default. This also applies to search engine and AI provider crawlers.

To request access, email abuse@eudoria.it from an official organizational address. Include a responsible contact, purpose and data use, requested domains and paths, User-Agent, verifiable source IP addresses or ranges, maximum request rate, concurrency and requested validity period. For feeds, also specify the service or API you need.

Requests are reviewed through an Odoo task. The EudorIA contact verifies the operator's identity and traffic source: a User-Agent alone is insufficient. Access requires explicit owner approval with a defined scope, limits and expiry. Receipt of a request or creation of a task does not grant authorization.

Automation must remain suspended until approval. Authorization may be revoked and does not permit aggressive scans or exceeding the agreed limits.

NIS2 and DORA

From obligations to operational evidence.

EudorIA uses NIS2 and DORA as references to structure digital risk management, incidents, continuity, suppliers, access, vulnerabilities, records and effectiveness verification.

The applicability of the regulations must be assessed for each organization. We do not offer a compliance label: we translate the relevant obligations into responsibilities, procedures and evidence defined in the contract and in the activated service.

Reports

Have you found a security issue?

Describe the observed behavior without including credentials or unnecessary personal data. The EudorIA security team will assess the report and get back to you if further information is needed.

Technical contact and abuse reports

Fatjon Celaj
abuse@eudoria.it

Send a report