Security model
A platform that can change every host it watches is a target. These are the controls that stand between that capability and someone misusing it.
Pull-only agents
Nothing connects to a monitored host. Agents open no listening port and reach the server on a heartbeat, which also means laptops behind NAT and hosts in segmented networks work without firewall exceptions towards them.
Signed commands
Every command is signed with HMAC-SHA256 using the agent's own token, and carries a timestamp. Agents refuse a command that is older than ten minutes or more than a minute in the future, so a captured command cannot be replayed later.
Roles and permissions
Seven built-in roles: Super administrator, Left Security Officer, Right Security Officer, Administrator, Analyst, Auditor and Viewer. You can create your own roles and give individual users extra grants or denials. When a grant and a denial meet, the denial wins.
Dual control
Critical actions wait for a second person to approve them. By default this covers changes to users and roles, the approval policy itself, containment, remediation, firewall pushes, deleting agents, licences, platform updates, API keys and agent releases.
The Left and Right Security Officers approve each other's requests, and nobody can approve their own. Pending requests appear under Approvals. Which actions need approval, and who approves whom, is set under Settings, Access control, Dual control.
Sign-in
- Two-factor authentication (TOTP) is required by default, with ten single-use recovery codes.
- The installation's first administrator must replace the one-time password before anything else opens.
- Passwords shorter than 12 characters, or well known, are refused.
- Single sign-on with OIDC is available; local sign-in remains for break-glass access.
API keys
Service accounts use API keys with one of three scopes: read-only, run scans or ingest. Keys are stored only as SHA-256 hashes.
Audit trail
Every action is recorded with the user, the time and, for critical actions, the approver. Audit records are kept for two years by default.
Delivery and updates
- Each bundle carries a signed manifest of every file in it.
- The server application ships compiled to native code for Intel/AMD and ARM.
- Licences are RSA-4096 signed and verified on your server, with no licence server and no telemetry.
- Agent releases are signed with a separate Ed25519 key held offline.
Where your data lives
On your server, in PostgreSQL and Redis on the internal container network. Neither is published on a host port. Nothing is sent to us.
Reporting a vulnerability
Write to [email protected].

