Skip to main content

Security

Built to be trusted with your most sensitive network.

A scanner touches everything, so Cyentrix is designed so the cloud sees as little as possible and can never reach into your network.

Security model

Least privilege, by architecture.

On-prem execution

All scanning runs on your node. Targets, credentials and raw evidence never leave your network — only sanitised findings sync for reporting.

Outbound-only

The node dials out over HTTPS and long-polls for jobs. No inbound ports, no VPN, and the console cannot initiate a connection to you.

Control/execute split

The console creates jobs and shows results; it has no scanning capability of its own. Execution is confined to nodes you run — enforced in software.

Credentials stay local

SSH / WinRM credentials for authenticated scans are stored and used on the node only. They are never transmitted to the cloud.

Tenant isolation

The multi-tenant control plane enforces database row-level security, so one organisation can never read another's data.

Hardened auth

Argon2id password hashing, server-side revocable sessions, optional TOTP two-factor, CSRF protection and rate-limited sign-in.

Signed updates

Node updates ship as cryptographically signed releases and are verified before they apply — an attacker can't push a malicious build.

Encryption in transit

All console and node traffic is TLS-encrypted end to end.

Data minimisation

The cloud stores only what it needs to manage scans and render reports — nothing more.

Responsible disclosure: found a security issue? Email security@cyentrix.com and we'll respond promptly.

Data flow, in detail

Know exactly what leaves your network.

See the full breakdown of what stays local and what syncs to the cloud.