Where your data lives
- Self-hosted
- Everything stays on your own server, connected or fully offline. cdnCore has no access unless you grant it for support.
- Managed by cdnCore
- Your data stays on your dedicated instance on cdnCore infrastructure in Portugal, connected to your network over a site-to-site VPN. The instance is not shared with other customers.
- One customer per installation
- Each installation holds the data of one organisation only, by design.
Updates and supply chain
- Signed update manifest
- Every update is verified against an Ed25519-signed manifest before it is applied.
- Pinned images and verified dependencies
- Container images are pinned by digest and dependencies are verified by hash.
- SBOM for every service
- A CycloneDX software bill of materials ships with each service, with the licence of each component and a third-party component list.
- Update with rollback
- "Apply Update" takes a backup first and supports rollback. Isolated networks use a signed offline bundle with offline rollback.
- Edge and stable channels
- Choose how quickly new releases reach your installation.
Identity and access
- Passwords and two-factor authentication
- Passwords are hashed with Argon2id. Two-factor authentication uses TOTP.
- Single sign-onEnterprise
- Connect your OIDC identity provider.
- Roles and per-device permissionsPro and Enterprise
- Full, read-write and read-only roles, narrowed per device where needed.
- Sessions and lockout
- Session list with method and country, remote revoke, account lockout and alerts on brute-force sign-in attempts.
- Sign-in protection
- Cloudflare Turnstile on sign-in and a forced password change at first sign-in.
Audit and evidence
- Hash-chained audit logPro and Enterprise
- Tamper-evident records with a "Verify chain" button, full-text search and CSV export.
- Sign-in log
- Every sign-in recorded, with a date filter.
- Audited remote sessions
- SSH sessions from the browser are audited without recording their content, and are limited to full administrators.
Secrets and AI data
- Encrypted secrets
- Notification-channel secrets and the Cloudflare token are stored encrypted and masked. Discovery credentials are erased after 24 hours.
- AI under your controlPro and Enterprise
- You choose the model provider, or host the model yourself. An input filter decides what the AI can see, every call is audited without its content, and AI can be switched off.
- Optional status mirror
- Off by default. When enabled it never sends device names, addresses, logs, metrics, users or credentials.
Current limits
- Two-factor authentication uses TOTP only; FIDO2/WebAuthn is not supported.
- Single node, with no geo-redundant high availability.
Documents and disclosure
The Data Processing Agreement and the subprocessor register are available on request from the Data Protection Officer at [email protected].
To report a suspected vulnerability, write to [email protected]. Please include enough detail to reproduce the issue.
See whether AtlasEye fits your operations.
Request a 14-day free trial for up to 25 devices with every feature enabled. A member of the team reviews each request within 48 business hours before activation.