CRODE CRODE

Resources · Architecture

How it works

The same operating model runs behind every CRODE product — provisioned in a cloud you own, secured by default, operated end-to-end by one engineer, and documented down to the transport layer so you can verify it rather than trust it.

01
Provision
Workloads spin up in your own cloud account. CRODE orchestrates; you own the substrate.
02
Secure
Hardened baseline, TLS 1.3, mutually-authenticated tunnels, short-lived rotating keys.
03
Operate
One engineer runs it end-to-end with a 24-hour response target and no support tiers.
04
Verify
We publish how it works instead of asking for trust — read the specs below.
99.98%
control-plane uptime
0
access logs kept long-term
TLS 1.3
on every surface
≤ 30d
full data purge on exit

SPEC-01

Control plane

Every system runs on a self-hosted control plane on infrastructure CRODE operates directly — no managed SaaS backend holding your metadata. Provisioning, monitoring and billing state live on servers we administer, not on a vendor's multi-tenant database.

Customer-facing workloads run on the cloud you choose. Crovi desktops are provisioned into Vultr, AWS or Oracle accounts, and Litescope agents report to an endpoint you control. CRODE orchestrates; you own the substrate.

SPEC-02

Transport & keys

All traffic between agents, control plane and operators is encrypted in transit. Session keys are short-lived and rotated; long-term secrets live in an isolated secret store, never in application config or logs.

In transitTLS 1.3 for all HTTP surfaces; mutually-authenticated tunnels for agent traffic.
Key rotationSession credentials rotated automatically; operator access is time-boxed.
At restVolume-level encryption on all control-plane storage.

SPEC-03

Operations

There is no support-tier ladder. The engineer who wrote the system answers the inbox, with a 24-hour response target. Change history is kept internally and summarised to affected customers directly rather than buried in a status widget.

Independent by design: CRODE is self-funded. No board pressuring growth at any cost, no acquirer waiting to sunset a product — systems are run for the long term. For what we never collect, see Security & no-log.