A smaller attack surface, and a record of every change
A SaaS estate spreads your data across vendors whose controls you read about in a report once a year. A self-hosted estate brings it back, but only helps if it is run with discipline: patched on time, reachable by few people, and recorded.
Pilae runs every deployment on the same model. Apps answer only on a private network, behind one hardened gate on port 443. Our engineers have named accounts with least privilege. The Pilae Agent plans every change with a backup and a rollback, and nothing applies without an approval. The full security model is published, and networks with no internet connection are covered by air-gapped deployment on Enterprise.
Security tools in your own estate
Some of the apps we operate are security tools in their own right, run for your teams on the same terms as any other app: a pinned version, daily backups, fixes applied in your window. Wazuh collects and correlates events from your servers and endpoints if you have no SIEM yet. OpenBao keeps application secrets and certificates out of configuration files. NetBird gives your own staff access to internal systems by identity and group, instead of a VPN that opens the whole network. Passbolt and Vaultwarden hold shared passwords, and Harbor scans the container images your developers build before they run.
Who is responsible for what
Security is shared between your organisation, Pilae and, in Pilae Cloud, the datacentre operator. The shared responsibility page sets out who owns each layer, from physical security to user accounts, so your risk register can name an owner for each control.
Evidence your auditors can use
Every plan, approval, command and result goes to the audit trail, which you can export to your SIEM. Restore tests are recorded every month, as described on the backups page. If a regulator asks how a change was made, the answer is already written down. For regulated sectors, see NIS2 and DORA and FINMA outsourcing, and for what Pilae and its providers hold, the certifications page.
Vulnerabilities in the platform can be reported to security@pilae.com, as described in our disclosure policy.