Skip to content
SECURITY AND TRUST

Your manuscript is not an ordinary data set.

Eloir protects writing flow and data with local availability, scoped account access and sync that makes conflicts visible.

Start for free See Eloir
01

Keep working locally

Your current working copy lives in the browser and remains available without an internet connection. Cloud sync is tied to your account.

02

Protected account access

Passwords are hashed. Production cookies are secure and unavailable to JavaScript. Account errors do not disclose whether an address is registered.

03

No silent overwrites

Each cloud project belongs to one account and carries a revision. If devices change the same project in parallel, both versions remain available for a decision.

04

A visible way out

Backup, export and account deletion remain visible. Deleting a cloud account does not automatically erase the current local copy.

TIME-LIMITED LINKS

A link works only as long as needed.

Confirmation and reset links lead only to approved Eloir addresses. Tokens are not stored in analytics events.

24 hoursEmail confirmation

A signed confirmation link. You can request a new one after it expires.

30 minutesPassword reset

A random server-side token that is consumed after successful use.

30 daysMaximum session

Regular renewal; a password reset revokes existing sessions.

TECHNICAL LAYERS

Protections already enforced.

  • TransportHTTPS and HSTS on the production domain
  • BrowserContent Security Policy, frame blocking and MIME protection
  • AccessSame-origin checks and rate limits for account actions
  • DataServer-side project ownership checks and bounded sync payloads
  • RecoveryEncrypted backups, an external copy and regular restore checks
  • PrivacyNo third-party trackers and no training with manuscripts

Security needs understandable choices.

Eloir shows account status, the local copy, cloud sync and conflicts separately, so you know where the current version lives.

Start for free