We hold threat data. We treat it that way.
Security isn't a feature bolted onto our platform — it's the constraint we design everything against. Here's how we protect what you trust us with.
Per-customer isolation
Every customer's findings live behind a strict tenant boundary enforced by the platform itself — not an application filter we hope is correct. It's continuously tested, so one customer's data can never surface to another.
Least privilege
Access to your data is scoped to exactly what a task needs and nothing more. Credentials are read-only where they can be, and independently revocable.
Encryption
Data is encrypted in transit with modern TLS. Secrets at rest are encrypted, and never exposed to the systems that don't need them.
Hardened edge
Public surfaces sit behind a managed WAF and DDoS protection, with the origin hidden and strict content-security policies on everything we serve.
Strong authentication
Multi-factor authentication for accounts, short-lived sessions, and API keys you control and rotate. We monitor our own login surfaces for abuse.
We watch ourselves
The same detection pipeline we run for customers watches our own platform. If someone probes our surfaces, it becomes an alert we investigate.
Built for European data obligations.
We operate with GDPR and NIS2 in mind. Monitoring is scoped to what you authorise, data is retained only as long as it's useful, and we never bypass a login or vetting step to obtain it.