LawlietLAWLIET
Book a demo

Security model

A platform that can change every host it watches is a target. These are the controls that stand between that capability and someone misusing it.

Pull-only agents

Nothing connects to a monitored host. Agents open no listening port and reach the server on a heartbeat, which also means laptops behind NAT and hosts in segmented networks work without firewall exceptions towards them.

Signed commands

Every command is signed with HMAC-SHA256 using the agent's own token, and carries a timestamp. Agents refuse a command that is older than ten minutes or more than a minute in the future, so a captured command cannot be replayed later.

Roles and permissions

Seven built-in roles: Super administrator, Left Security Officer, Right Security Officer, Administrator, Analyst, Auditor and Viewer. You can create your own roles and give individual users extra grants or denials. When a grant and a denial meet, the denial wins.

Dual control

Critical actions wait for a second person to approve them. By default this covers changes to users and roles, the approval policy itself, containment, remediation, firewall pushes, deleting agents, licences, platform updates, API keys and agent releases.

The Left and Right Security Officers approve each other's requests, and nobody can approve their own. Pending requests appear under Approvals. Which actions need approval, and who approves whom, is set under Settings, Access control, Dual control.

Sign-in

API keys

Service accounts use API keys with one of three scopes: read-only, run scans or ingest. Keys are stored only as SHA-256 hashes.

Audit trail

Every action is recorded with the user, the time and, for critical actions, the approver. Audit records are kept for two years by default.

Delivery and updates

Where your data lives

On your server, in PostgreSQL and Redis on the internal container network. Neither is published on a host port. Nothing is sent to us.

Reporting a vulnerability

Write to [email protected].