On-prem execution
All scanning runs on your node. Targets, credentials and raw evidence never leave your network — only sanitised findings sync for reporting.
Security
A scanner touches everything, so Cyentrix is designed so the cloud sees as little as possible and can never reach into your network.
Security model
All scanning runs on your node. Targets, credentials and raw evidence never leave your network — only sanitised findings sync for reporting.
The node dials out over HTTPS and long-polls for jobs. No inbound ports, no VPN, and the console cannot initiate a connection to you.
The console creates jobs and shows results; it has no scanning capability of its own. Execution is confined to nodes you run — enforced in software.
SSH / WinRM credentials for authenticated scans are stored and used on the node only. They are never transmitted to the cloud.
The multi-tenant control plane enforces database row-level security, so one organisation can never read another's data.
Argon2id password hashing, server-side revocable sessions, optional TOTP two-factor, CSRF protection and rate-limited sign-in.
Node updates ship as cryptographically signed releases and are verified before they apply — an attacker can't push a malicious build.
All console and node traffic is TLS-encrypted end to end.
The cloud stores only what it needs to manage scans and render reports — nothing more.
Responsible disclosure: found a security issue? Email security@cyentrix.com and we'll respond promptly.
Data flow, in detail
See the full breakdown of what stays local and what syncs to the cloud.