Security of the platform itself.

A tool that watches your network has to be trustworthy in its own right. This page describes how AtlasEye is built, updated and accessed, and where your data is kept.

Where your data lives

Self-hosted
Everything stays on your own server, connected or fully offline. cdnCore has no access unless you grant it for support.
Managed by cdnCore
Your data stays on your dedicated instance on cdnCore infrastructure in Portugal, connected to your network over a site-to-site VPN. The instance is not shared with other customers.
One customer per installation
Each installation holds the data of one organisation only, by design.

Updates and supply chain

Signed update manifest
Every update is verified against an Ed25519-signed manifest before it is applied.
Pinned images and verified dependencies
Container images are pinned by digest and dependencies are verified by hash.
SBOM for every service
A CycloneDX software bill of materials ships with each service, with the licence of each component and a third-party component list.
Update with rollback
"Apply Update" takes a backup first and supports rollback. Isolated networks use a signed offline bundle with offline rollback.
Edge and stable channels
Choose how quickly new releases reach your installation.

Identity and access

Passwords and two-factor authentication
Passwords are hashed with Argon2id. Two-factor authentication uses TOTP.
Single sign-onEnterprise
Connect your OIDC identity provider.
Roles and per-device permissionsPro and Enterprise
Full, read-write and read-only roles, narrowed per device where needed.
Sessions and lockout
Session list with method and country, remote revoke, account lockout and alerts on brute-force sign-in attempts.
Sign-in protection
Cloudflare Turnstile on sign-in and a forced password change at first sign-in.

Audit and evidence

Hash-chained audit logPro and Enterprise
Tamper-evident records with a "Verify chain" button, full-text search and CSV export.
Sign-in log
Every sign-in recorded, with a date filter.
Audited remote sessions
SSH sessions from the browser are audited without recording their content, and are limited to full administrators.

Secrets and AI data

Encrypted secrets
Notification-channel secrets and the Cloudflare token are stored encrypted and masked. Discovery credentials are erased after 24 hours.
AI under your controlPro and Enterprise
You choose the model provider, or host the model yourself. An input filter decides what the AI can see, every call is audited without its content, and AI can be switched off.
Optional status mirror
Off by default. When enabled it never sends device names, addresses, logs, metrics, users or credentials.

Current limits

  • Two-factor authentication uses TOTP only; FIDO2/WebAuthn is not supported.
  • Single node, with no geo-redundant high availability.

Documents and disclosure

The Data Processing Agreement and the subprocessor register are available on request from the Data Protection Officer at [email protected].

To report a suspected vulnerability, write to [email protected]. Please include enough detail to reproduce the issue.

See whether AtlasEye fits your operations.

Request a 14-day free trial for up to 25 devices with every feature enabled. A member of the team reviews each request within 48 business hours before activation.

Request free trial