Security is the product
We build threat intelligence infrastructure. Our own security practices reflect the same rigor we bring to our customers.
SOC 2 Type II
NodeSight undergoes annual SOC 2 Type II audits covering security, availability, and confidentiality trust service criteria. Our latest report is available under NDA to enterprise customers.
Air-gapped deployment
For government and critical infrastructure customers, NodeSight sensors operate in fully air-gapped environments. No internet connectivity required. Offline model updates delivered via verified, signed packages.
Encryption
All data encrypted at rest (AES-256-GCM) and in transit (TLS 1.3 with mutual authentication). Forensic evidence chains use SHA-256 hash chains for tamper detection. Key management via HashiCorp Vault.
Access control
Role-based access control (RBAC) with mandatory MFA. Privileged access requires hardware security keys (FIDO2). All access events logged to immutable audit trails.
Incident response
Documented incident response procedure with 4-hour initial response SLA. Customers are notified within 24 hours of any security incident affecting their data. Post-incident reviews published within 72 hours.
Supply chain security
All dependencies pinned to verified hashes. Build pipeline produces reproducible artifacts. Sensor binaries signed with ed25519 keys. SBOM (Software Bill of Materials) provided to enterprise customers.
Responsible disclosure
We welcome responsible disclosure of security vulnerabilities. If you discover a vulnerability in NodeSight's systems, please report it to:
We ask that you:
- → Allow 90 days for remediation before public disclosure
- → Do not access or modify customer data
- → Do not degrade service availability
- → Provide sufficient detail to reproduce the vulnerability
We do not pursue legal action against researchers acting in good faith.