Security is the product.
SheerSight watches your whole stack, so we built it to hold as little of your risk as possible, and to prove exactly what it did. Here is how that works, in plain terms.
A dedicated instance, yours alone
Your telemetry runs on a hardened instance that is yours, with no shared tenancy and no neighbours. It dials out to us; nothing dials in to it.
Secret-free control plane
Your credentials are encrypted in your browser, to your box, before they ever leave. We relay ciphertext only, so only your instance can decrypt. The control plane never holds a key it could lose.
Signed, allow-listed commands
Every action we send your instance is cryptographically signed and verified there. Your agent runs only a fixed allow-list of parameterized operations, never an arbitrary command.
Tamper-evident audit ledger
Every command, disposition and change lands in a hash-chained ledger. Nothing can be quietly rewritten after the fact, including by us.
Access-gated & MFA-enforced
The console sits behind Cloudflare Access with multi-factor login. Operator routes fail closed, so a missing or invalid identity is refused, never assumed.
Strict tenant isolation
Every request is scoped to your tenant on the server. One customer can never read another customer's data, whatever the client sends.
What we store, and what we never touch
We never hold your secrets. API keys, tokens and credentials are envelope-encrypted in your browser to your instance's recipient; our servers only ever see opaque ciphertext. There is no column, log, or backup anywhere in our control plane that contains a plaintext credential.
We store detection metadata, not your raw data. To give you the fleet view, your instance replicates alert, incident, suppression and KPI metadata into our control plane. Your underlying logs and source data stay on your box.
The request-access form is privacy-minimizing. It stores a salted, one-way hash of the submitter's IP for abuse control, never the raw address, and prunes it on a fixed retention window.
The guarantees we hold ourselves to
- No plaintext secret ever exists on our servers.
- No inbound connection is ever made to your environment.
- All operator access is identity-gated, MFA-protected, and logged.
- Commands are signed and constrained to a parameterized allow-list.
- The audit trail is hash-chained and tamper-evident.
- Telemetry is minimized and retention-bound.
- Enrolment is one-time and revocable; offboarding revokes access and agents.
Report a vulnerability
If you believe you have found a security issue, we want to hear from you. Email support@sheersight.io with the details and steps to reproduce. We will acknowledge your report and work with you on a fix. Please give us reasonable time to respond before any public disclosure.