Security and trust

A security product should survive its own audit.

This page is what we would want to read before installing someone else's agent on our fleet: how the platform protects itself and your data.

Product security

How the platform protects itself.

Encrypted in transit, everywhere

Agents, log shippers, syslog senders and browsers all talk TLS. Certificates are issued automatically, and log ingest uses its own certificate authority you distribute to senders.

A credential per agent

An agent presents a bootstrap token once, at enrolment, and receives its own credential, so every endpoint's access is its own.

Outbound-only agent

The agent connects outbound, so the endpoint's inbound firewall stays closed.

Short-lived response sessions

A live shell opens with a ticket bound to a named operator and a single host, valid for a minute. Fleet credentials stay on the server.

Roles enforced on the server

Admin, lead, analyst and viewer, with per-organization grants checked in every query. Resources outside a grant stay invisible.

Signed agent updates

Self-update verifies a signature against a key pinned at install time. Only builds signed by FluenceSecurity are applied.

Least privilege inside

Every component runs with only the access it needs. The customer portal reaches customer-facing data only.

Tested before it ships

Every release passes automated test suites across the whole platform. Backups are scripted, and the restore drill is part of the runbook.

Your data

Where it lives, who can read it, how long it stays.

  • Self-hosted: on your server, under your administration. Your telemetry stays with you.
  • Hosted tenant: a dedicated deployment in the EU under the xdr.fluencesecurity.com domain, with its own data store.
  • AI: alert evidence goes only to the model endpoint you configure. Point it at your own hardware and it stays inside the deployment. AI is opt-in.
  • Retention is a documented setting per data type. Defaults are 90 days for events, 14 days for unparsed events and 365 days for the audit trail.
  • Every action by a person, a playbook or the platform itself is attributed and kept in the audit trail for a year.
  • Your data is used only to protect your organization.

Vulnerability disclosure

Found something?

We want to hear about it. Our disclosure policy explains scope, safe harbour and how we handle reports; security.txt points to it from every deployment.

Audit and procurement

Ready for your auditor.

  • An attributable audit trail of every human and automated action, kept for a year.
  • Retention documented per data type, with defaults you can change.
  • A data processing agreement and a published subprocessor list.
  • Security questionnaire answers on request, written by the people who build the platform.

Need answers for procurement?

Send us your security questionnaire. We answer it ourselves, in plain language, long ones included.