Security
Security
This page says how we keep your phone and your API key separate from everyone else's, what we store, and what we have not done yet.
1
How your phone is isolated.
Between customers
- Each phone is its own Android 13 container with its own storage volume.
- Each account has its own private network on our server.
- A phone cannot open a connection to another account's phone, to another phone in the same account, or to the server it runs on. It can reach the internet.
- We checked this on 5 October 2026 from inside a test phone. Connections to other phones, to the server and to the hosting provider's metadata address were all blocked.
- An API key only works for the phones of its own account.
- A request for any other phone gets the same
403answer, whether that phone belongs to someone else or does not exist. A key cannot be used to find out which other phones exist. - The phone's debug port (adb) is not open to the internet. It listens only on the server itself, and the phone is set to accept only our management key.
- Each phone has its own CPU, memory and process limits.
- The API has no admin endpoint and no master key. Every key belongs to exactly one account.
Outbound internet address
- Phones do not go out to the internet from the address of our website and API.
- An account can be given its own outbound IP address. We have three such addresses today.
- Accounts without their own address share one pool address. All phones in one account share that account's address.
- All of these are data-centre addresses. See what we do not do yet.
The demo phone
- The 90-second demo on our homepage runs on one of our own phones. It is not a customer phone.
- Visitors never get an API key. The demo server keeps the key and gives the browser a random token that stops working after 90 seconds.
- One visitor uses the demo phone at a time.
- A visitor can look at the screen, tap, swipe, scroll and press navigation keys. A visitor cannot type text, or install, launch or remove apps.
- After each session the demo server closes the open apps and returns to the home screen. It does not wipe the phone.
- A customer key cannot reach the demo phone. We tested this with a test account's key and got
403. - The demo phone is in the same internal account as our other test phones. It does not have an account of its own yet.
2
Your API key.
- Your key is 256 random bits, generated on our server. It is shown once, when it is created.
- We store only a SHA-256 hash of the key. We cannot read your key back or show it to you again.
- An account can hold more than one key, so you can switch to a new key without downtime.
- When we revoke a key, we delete its hash. The API reads the change on the next request, without a restart.
- Every API request is logged with a short fingerprint of the key, not the key. Failed key attempts are logged the same way.
- The API accepts up to 30 requests per second from one IP address, with bursts to 60.
In the dashboard
- You sign in to the dashboard with your API key. There is no separate password.
- The dashboard keeps the key in your browser's local storage. It does not use cookies.
- The dashboard never shows the key in full. It shows only the last four characters.
- The dashboard signs you out after 30 minutes without activity. You can change this to 15 minutes, 1 hour or 4 hours.
- Signing out removes the key from that browser. It does not revoke the key, so your agents keep working.
- The dashboard server holds no keys of its own. It passes your key to the API, and the API does the checks.
You cannot create, rotate or revoke a key yourself yet. Email info@eriusphone.com and we do it for you. If you think a key has leaked, tell us straight away.
3
Data in transit and at rest.
In transit
- The website, the dashboard, the API and the demo are served over HTTPS only. Plain HTTP requests are redirected to HTTPS.
- Our server accepts TLS 1.2 and TLS 1.3. It refuses TLS 1.0 and 1.1.
- The certificates are issued by Let's Encrypt.
- The website and the API hosts send an HSTS header with a one-year lifetime.
At rest
- Everything runs on one server, in a Hetzner data centre in Helsinki, Finland.
- Your phone's storage is a volume on that server. It persists between sessions and restarts, so your apps, sign-ins and files stay until the phone is removed.
- When we remove a phone, our removal script deletes its container and its storage volume. We do this by hand, on request.
- An APK you upload is deleted from our temporary folder after it is installed.
- The server's disk is not encrypted by us. Phone storage is not end-to-end encrypted from us.
- People who operate the server can technically access what is on a phone. Our privacy policy says when we would.
- What exactly is deleted when you close your account, and how fast, is still being defined. The removal script covers your phones. Stored APK files, log entries and backups are not covered by a written procedure yet.
Passwords and sign-ins on the phone
- You sign in to your apps yourself, on the phone's live screen in the dashboard.
- We do not ask for your app passwords, and the API has no feature that stores them.
- Text typed on the phone is not written to our logs.
- This is a rule for using the product, not a technical lock. The API's
typeaction types whatever it is sent. Do not give your agent your passwords.
4
What we store about you.
When you request early access
- The form stores your email address, the time, your IP address, your browser's user agent, the site it was sent from and a campaign tag.
- It is stored in a SQLite database file on our server. Only the service that writes it and the server's administrators can read the file.
- A daily copy of that file is kept on the same server for 14 days.
- Each request also sends a notification email to our own mailbox, through our email provider.
When you visit this website
- We count page views and demo opens on our own server. Each count holds the time, the event name and a campaign tag. It holds no IP address and no visitor ID.
- This website sets no cookies.
- No page loads third-party analytics or advertising trackers. The Blog page loads one script from our blog provider, Soro. No other page loads a third-party script.
- Our web server keeps standard access logs (IP address, page requested, user agent) for 14 days.
When you use the API
- We store an account name and the hashes of your keys.
- The API log records the time, your account, the key fingerprint, the IP address, the method, path, phone and action, the status and how long it took.
- For app installs, launches, stops and uninstalls it also records the app's package name.
- The API log does not record request bodies. That means no typed text, no URLs your agent opens and no API keys.
- The log file is replaced when it reaches 50 MB, and one older file is kept. We have not set a fixed retention period yet.
The full list, and how to ask for a copy or for deletion, is in the privacy policy.
5
What we do not do yet.
Erius Phone is in early access. These are the gaps we know about.
- No certifications. We hold no security or privacy certifications, and we do not claim compliance with any specific regulation.
- Containers, not virtual machines. All phones share the server's kernel, and each container runs in privileged mode. The network and key checks above do not protect against a kernel-level escape.
- No encryption at rest by us. The server's disk is not encrypted by us, and phone storage is not end-to-end encrypted from us.
- Outbound IP addresses are limited. We have three outbound addresses. Not every account gets its own, and accounts without one share a pool address.
- Data-centre IP addresses. Apps and platforms can see that a phone connects from a data centre. Some limit or ban accounts for that, or for automated use. We cannot prevent it.
- No self-service keys. You cannot rotate or revoke a key yourself. Keys do not expire on their own, and a key cannot be limited to certain IP addresses.
- No second factor in the dashboard. The API key is the only credential.
- One server. There is no second server to take over, and no uptime guarantee.
- No backup job for phone storage. We run none on the server. Keep your own copies of anything important.
- No online payments. We do not take payments on this website yet, so we hold no card data.
- No fixed retention periods. Log retention and the account-closure procedure are still being defined.
- No bug bounty. We have no formal disclosure policy and no
security.txtfile yet.
6
Report a problem.
Found a security problem?
Email info@eriusphone.com. Tell us what you found and how to reproduce it.
Please do not access, change or delete another customer's data while testing. We do not pay bounties.
Give your agent a phone.
Early access: no payment, no card.
Request a device