---
id: "cloud.seguranca-e-dados"
titulo: "Elyra Cloud security and data"
resumo: "Where the data lives, how access reaches the computer that is the Cloud and who can sign in."
idioma: "en"
tipo: "conceito"
categoria: "cloud"
aplicavelDesde: "0.0.16"
capabilities: []
estadoEditorial: "aprovado"
nivelEvidencia: "artefato-distribuido"
refFonte: "e593bd0591d172fd8fb2c40f2c38f5bb52980eb3"
revisaoFonte: "2026-10-04"
revisor: "mantenedor (autorizou a publicação, 2026-10-04)"
rota: "/docs/en/cloud/seguranca-e-dados/"
fonte: "pt-br/cloud/seguranca-e-dados.md"
caminhoPublico: "docs/publica/en/cloud/seguranca-e-dados.md"
hashFonte: "sha256:35d81e55fd57bb5daeceaa78ef59cd23b3b3f3f3b8b3ae5dfd0227c04945b97d"
hashDestaPagina: "sha256:f968b201d55a5182799512fb4b2ea173cd3615125129b599763df2c2d77e9d82"
traducaoAssistidaPorIA: true
traducaoDesatualizada: false
corpoRetido: false
---
<!-- traducao-assistida-por-ia: idioma=EN fonte=pt-br/cloud/seguranca-e-dados.md fonteHash=sha256:35d81e55fd57bb5daeceaa78ef59cd23b3b3f3f3b8b3ae5dfd0227c04945b97d estado=atual -->

## Where your data lives

On the **computer that is your Cloud**: your Windows, Mac or Linux machine, or the Linux server where you
installed it. That computer is the one that runs the terminals, Git and the files.

The Elyra account stores what is needed for access to work: the license, the activated device (which uses
one device of the license), the link between the address and the computer, and the sign-in sessions.

## How access reaches your Cloud

- The Cloud listens **only inside the computer itself**: it accepts local connections only. No port is
  opened to the internet.
- Access from outside arrives through the **Elyra address** (`https://<your-username>-cloud.elyra.sh`), over
  **HTTPS**, through a connection that the computer itself opens from the inside out.
- Access only opens **after the Cloud is turned on** and the account confirms the license.

## Who signs in

- Sign-in goes through the **Elyra account**, with a **code sent by email** as a second factor.
- Only the **owner of the license** of the server signs in: the server refuses the authorization of any other
  account.
- The authorization the account hands to the browser is **single-use**, and the server keeps the ones
  already used, even after restarting.
- The session lasts 15 minutes and is renewed with the account every 10. If the account goes offline, the
  session continues for up to 1 hour after the last renewal.
- **Signing out of the account in this browser** ends that browser's session, on the server too. The others
  continue. Signing out of the license on the computer that serves the Cloud drops all sessions, and you can
  also end sessions in the account panel.
- The server stores sessions on disk only as the **hash** of the token, never the token itself.

## What stays on the computer

- The **license** is encrypted with the system's own key (DPAPI on Windows, Keychain on macOS, libsecret on
  Linux): copied to another computer, it does not open. On Linux without libsecret, common on headless
  servers, it is kept in a text file in the Cloud profile, with permission restricted to your user (0600),
  and the Cloud warns about this on startup.
- On a **headless Linux server**, the installer writes a minimal **passwordless `sudo` rule**: your user can
  run, as root, only turning linger on and off, `dpkg -r elyra` and deleting the rule's own file. It serves
  the [uninstall](/docs/en/cloud/desinstalar/), which removes it last.

## Next steps

- [Access from the browser](/docs/en/cloud/acessar-pelo-navegador/)
- [Uninstall](/docs/en/cloud/desinstalar/)
