Operate / Security

Security & data

Where Cenovel keeps your data, who can reach it, and how releases, secrets, backups and the audit trail are protected.

OperateReviewed against the application source on 3 October 2026

Where your data lives

Cenovel runs on the district’s own appliance or VM. Inventory, topology, device observations, work records and E-Rate records are stored and served there. The console reports its own performance measurements to the appliance’s API. Optional services connect only to the destinations you configure: Microsoft Entra ID sign-in, email, webhooks, site collectors and off-box backups.

Sign-in and access

Sign in with the local recovery account created at first boot, or configure Microsoft Entra ID sign-in (authorization code with PKCE). Access tiers and page permissions decide what each person can see and do, and department scope limits whose records they reach. Review both group mappings and individual role assignments.

See also: Permissions and departments · Configuration & access

Secrets

Day-to-day settings live in the console. File-based secrets are provisioned separately: on the native appliance they are protected credential files under /etc/cenovel/credentials, and deployment settings are checked in /etc/cenovel/appliance.conf.

Signed releases

The native installer and updater accept signed .cenovel bundles verified against a trusted public key before anything is staged. Upgrades run preflight checks, migration controls and a readiness gate.

See also: Upgrades & rollback

Backups

Native backup sets are encrypted and authenticated. Keep the backup keyring separately, configure an off-box copy, and use the restore drill to check that a set restores into a working console.

See also: Backup & restore

Audit trail and retention

Changes are recorded in an audit trail with an integrity chain you can verify and export. Records with funding, E-Rate, disposal, replacement or RMA history are never removed for good and show how long they must be kept.

See also: Audit history and evidence · Run an E-Rate cycle

Describes the release being prepared for deployment. Check the behavior on your installed release.

↑ ↓ to moveEnter to openEsc to close