โ—† Trust Center

Security, by design.

Apate is a passive, read-only monitor built so it cannot become the breach. This page summarizes our security posture, how we handle data, and where we stand on formal attestations - stated honestly, not overclaimed.

Security at a glance

Built so it can't be weaponized.

๐Ÿ‘๏ธ

Passive & read-only

It only observes. It cannot block, quarantine, push config or modify any device - so it can't be turned into a control plane.

๐Ÿšช

No inbound exposure

Sensors push outbound only. No listening port is opened on monitored segments - it works even from OT and air-gapped networks.

๐Ÿงฉ

No endpoint agent

Network-level and passive. No driver or agent on your endpoints, so no added endpoint attack surface and no fleet-crash risk.

๐Ÿข

Self-hosted

Runs on your infrastructure. No mandatory third-party cloud; your telemetry never has to leave your environment.

๐Ÿ”’

Encrypted & authenticated

TLS in transit, token-based RBAC, and a tamper-evident audit log of every action.

๐Ÿ“‰

Data-minimized

Posture and metadata only - never packet payloads, files or credentials. Storage is bounded, not an ever-growing data lake.

Compliance & certifications

Transparent about where we are.

Design-partner engagements run under NDA while formal attestations are completed.

โœ“

In place today

Passive/read-only design, TLS transport, RBAC, audit logging, on-prem data residency and data minimization.

โ—

In progress

SSO (SAML/OIDC), code-signed builds, an independent penetration test, a DPA and this Trust Center.

โ—‹

Planned

SOC 2 Type II and ISO 27001, high-availability and multi-tenant deployment, and cross-platform sensors.

Data handling

Frugal with data, by design.

A sensor's snapshot carries posture and metadata only. Because Apate is passive and content-free, large parts of a standard vendor security questionnaire simply don't apply - which shortens review rather than lengthening it.

  • Collected: posture score & grade, finding counts, device inventory metadata, event metadata
  • Never collected: raw packet payloads, files, credentials or user content
  • Encrypted in transit (TLS); at rest it lives in your own store, under your controls
  • You choose region and retention - straightforward for GDPR / data-residency
Apate console - posture and metadata only, read-only
Access & data flow

Least privilege, fully accountable.

๐Ÿชช

Role-based access & SSO

Three least-privilege roles - admin, viewer and write-only ingest. SSO via OIDC (Okta / Entra ID) maps your IdP group to the Apate role; MFA is enforced by your IdP.

๐Ÿงพ

Audit trail

Every write, privileged read and auth failure is logged with time, role, a non-reversible token fingerprint, path, status and source IP.

๐Ÿ—„๏ธ

No required subprocessor

Self-hosted - your data does not pass through Apate-operated cloud services. Optional IP-intelligence lookups run only to providers you enable with your own keys.

๐Ÿ›ฐ๏ธ

Outbound-only data flow

Sensors push posture snapshots outbound over TLS to your own collector. Nothing dials into a monitored segment.

Responsible disclosure

Report a vulnerability.

We welcome responsible disclosure. Email security@apatesecurity.com with details and steps to reproduce; we'll acknowledge and work with you on a fix. Please don't publicly disclose until we've had a reasonable chance to remediate.