Skip to main content

Frequently Asked Questions

Who has access to your data on the Paragon side?

Unmanaged on-premise: Your data stays in your installation. Paragon has no access to your cloud console, databases, or logging tools. Paragon can only use the product Dashboard if you choose to provision a user seat for support. Managed on-premise: Your data stays in your cloud account. You own the cloud console. Paragon operates the installation using installer credentials you grant, sandboxed to the dedicated account, tenant, or project. Dashboard access exists only if you provision a Paragon user seat. Database and logging access is used on demand for support, troubleshooting, and upgrades—not for continuous browsing of customer data. Cloud hosted: Paragon operates the multi-tenant service and has continuous operational access. Customers do not have direct access to the underlying databases or logging tools.

What type of access is required for managed installations?

The Paragon installer needs credentials to provision and update application resources, for example through Terraform. Those credentials are scoped to the dedicated AWS account, Azure tenant and subscription, or GCP project, so the installer cannot manage unrelated resources in your organization. You control that access through your cloud IAM and can restrict or revoke it. Restricting or revoking access may affect support and upgrade SLAs. For support requests, Paragon engineers use a bastion or secure tunnel to access application logs and databases as needed for troubleshooting and maintenance. Metrics dashboards in Grafana contain operational metrics and do not include end-user PII.

How is access limited to support engineers?

On managed installations, support access is limited to authorized personnel, used for customer-requested support and maintenance, and is not a substitute for your own cloud-console ownership. Network access to administrative endpoints is restricted, for example through allowlisted IPs and key-based or tunneled access. On unmanaged installations, Paragon has no infrastructure access by default.

Is there an audit trail for access?

Managed on-premise: You can audit infrastructure-level activity in your cloud provider logs, such as AWS CloudTrail, GCP Cloud Audit Logs, or Azure Monitor. Paragon also logs access requests internally. Unmanaged on-premise: You have full audit capability in your environment. Cloud hosted: Customer-visible audit of Paragon’s operational access is not available.

Can Paragon see my end users’ data?

Event logs and workflow execution data live in your deployment’s Postgres, object storage, and logging tools. On managed installations, authorized Paragon personnel may view logs or related diagnostics when fulfilling a support request. Credentials and secrets are encrypted at rest and are not used as a support debugging surface. On unmanaged installations, Paragon can only see Dashboard data if you provision a seat.

Is Paragon’s access continuous or on-demand?

  • Cloud hosted: Continuous operational access
  • Managed on-premise: Installer and operations access to run the service; bastion or database access is for support and upgrades, not continuous monitoring of customer payloads
  • Unmanaged on-premise: On-demand Dashboard access only, and only if you provision a seat