Security

Clear boundaries. Safer operations.

Self-hosted control, guarded actions, and an audit trail make the operating boundary visible instead of implicit.

Agentless evidence

Management uses validated SSH and read-only SNMP where applicable, without installing an agent on managed systems.

Narrow privilege

Dedicated non-root access and narrowly scoped privilege keep administrative reach explicit.

Credential boundaries

Encrypted credential storage protects configured secrets, and no secret is returned after creation.

Approved host trust

Pinned host identity and explicit trust approval help prevent an unexpected system from being accepted silently.

Bounded collection

Purpose-limited collection uses response limits, timeouts, and redaction to constrain retained evidence.

Guarded actions

Typed actions, previews, and explicit confirmation replace arbitrary shell or unrestricted commands.

Auditable recovery

Approval and audit records sit beside rollback and recovery controls for supported changes.

Self-hosted lifecycle

You retain the control plane in your environment and apply signed releases through a visible update boundary.