Security & compliance

What PROSENTRIQ actually does with your data, what it can prove to an auditor, and how to reach us if something's wrong.

Compliance evidence, generated on demand

The same evidence report a running deployment can generate today — JSON, Markdown, or a signed-checksum PDF — maps directly to these controls.

FrameworkControlWhat PROSENTRIQ provides as evidence
SOC 2 CC7.2 Continuous monitoring for anomalies indicative of malicious activity, with a timestamped event log and automated-response record.
PCI DSS v4.0 Req. 10.2.1 / 11.5 Audit logging on all monitored components, plus active intrusion-detection with documented, current rule updates.
HIPAA Security Rule 45 CFR 164.312(b) Audit controls that record and examine activity on systems handling electronic protected health information.

Reports include a SHA-256 checksum sidecar so an auditor can verify a copy hasn't been altered after generation. See compliance/reports/generate_report.py for the exact query logic behind every figure in a report.

What we collect, and what we deliberately don't

  • Account email and hashed API key, for authentication and billing.
  • Anonymized indicators — attacker IPs, cryptographic hashes of malicious payloads — shared with the Threat Hub to improve fleet-wide detection.
  • Behavioral baselines and event scores, stored on your own infrastructure by default.
  • File contents or kernel memory dumps are never uploaded.
  • Your proprietary code or user traffic logs are never transmitted.
  • No hardware/device identifiers are collected — accounts are authenticated by API key alone.

Read the full Privacy Policy

firewall_probe.c
// prosentriq_observe.c -- the trial-mode probe.
// Deliberately has NO blocklist lookup and NO
// XDP_DROP / redirect code path -- not disabled,
// removed. It cannot enforce even if told to.
 
return XDP_PASS;

Reporting a vulnerability

Found a security issue in PROSENTRIQ itself — the agent, the Detection API, or this site? We want to know before anyone else does.

Email [email protected] with as much detail as you can. We ask that you:

  • Give us a reasonable window to fix the issue before public disclosure.
  • Avoid accessing or modifying data that isn't yours in the course of testing.
  • Include steps to reproduce, affected component/version, and impact.

We aim to acknowledge reports within 2 business days.

Fail-open, by design

Detailed in the architecture documentation, summarized here because it's a security property, not a feature: