Apate is a passive, read-only monitor built so it cannot become the breach. This page summarizes our security posture, how we handle data, and where we stand on formal attestations - stated honestly, not overclaimed.
It only observes. It cannot block, quarantine, push config or modify any device - so it can't be turned into a control plane.
Sensors push outbound only. No listening port is opened on monitored segments - it works even from OT and air-gapped networks.
Network-level and passive. No driver or agent on your endpoints, so no added endpoint attack surface and no fleet-crash risk.
Runs on your infrastructure. No mandatory third-party cloud; your telemetry never has to leave your environment.
TLS in transit, token-based RBAC, and a tamper-evident audit log of every action.
Posture and metadata only - never packet payloads, files or credentials. Storage is bounded, not an ever-growing data lake.
Design-partner engagements run under NDA while formal attestations are completed.
Passive/read-only design, TLS transport, RBAC, audit logging, on-prem data residency and data minimization.
SSO (SAML/OIDC), code-signed builds, an independent penetration test, a DPA and this Trust Center.
SOC 2 Type II and ISO 27001, high-availability and multi-tenant deployment, and cross-platform sensors.
A sensor's snapshot carries posture and metadata only. Because Apate is passive and content-free, large parts of a standard vendor security questionnaire simply don't apply - which shortens review rather than lengthening it.

Three least-privilege roles - admin, viewer and write-only ingest. SSO via OIDC (Okta / Entra ID) maps your IdP group to the Apate role; MFA is enforced by your IdP.
Every write, privileged read and auth failure is logged with time, role, a non-reversible token fingerprint, path, status and source IP.
Self-hosted - your data does not pass through Apate-operated cloud services. Optional IP-intelligence lookups run only to providers you enable with your own keys.
Sensors push posture snapshots outbound over TLS to your own collector. Nothing dials into a monitored segment.
We welcome responsible disclosure. Email security@apatesecurity.com with details and steps to reproduce; we'll acknowledge and work with you on a fix. Please don't publicly disclose until we've had a reasonable chance to remediate.