Skip to main content
Argbaan
Free consultation
Security and trust

Your security data stays on your own hardware

Argbaan has to protect exactly what it asks you to trust it with. This page says where your data is, who can reach it and on what terms, and how we have limited ourselves.

Layered glass shields around a citadel — defence in depth
Data

What is kept where

On your Arg Box

  • Your network map, devices and servers
  • Alerts, events and the decisions you made
  • Monthly reports and the notification delivery log
  • Panel accounts and sign-in history

What reaches Argbaan

  • The Arg Box's own health: up or down, versions, temperature, disk space
  • Only if you choose: alert counts, or alert titles for managed services
  • Support tickets you open yourself

You set the sharing level in your own panel, and Argbaan cannot raise it.

An alert text message is the only thing sent through Argbaan; it carries a severity and a short code, and Argbaan keeps neither the number nor the text.

Access

Who can get in

  • Two-step sign-in

    Passwords are kept with argon2id and backed by a second factor. Your organisation can make it mandatory for every member.

  • Support access on your say-so

    An Argbaan engineer can only ask, with a reason and a duration. Access opens only when you approve with your password, and closes itself when the time is up.

  • Limits on ourselves

    Argbaan's engineers cannot sign in to our console without a second factor, and releasing to every customer or wiping an Arg Box needs a second engineer's approval.

  • A trail no one can edit

    Every sign-in, approval and important change, on your Arg Box and in our console, goes to a log that not even our own software can edit or delete.

Updates

How an update reaches your Arg Box

  1. 01

    Signed away from the network

    Every release is signed with Argbaan's Ed25519 key; nothing without a signature and a checksum is offered to any Arg Box.

  2. 02

    Released in stages

    Each release runs first on lab and internal devices and a small group of customers, and only then reaches everyone.

  3. 03

    Checked on the Arg Box

    The Arg Box checks the signature and the checksum itself, and never goes back to a version older than the newest it has installed.

  4. 04

    Installed beside the current one

    The new version is installed next to the running one; if its health check fails, the Arg Box switches back on its own.

Engineering

How we build the software

  • Organisations kept apart in the database

    Every row belongs to one organisation, and the database itself refuses to read another's; this is tested on every build.

  • No known vulnerable dependencies

    A release with a known vulnerability in its libraries does not ship.

  • Content security policy

    The panel and the console run only scripts stamped with a single-use value for that very page; an injected script does not run.

  • Encrypted backups with your key

    The Arg Box backs itself up every night, encrypted, and only you hold the key that opens the backup.

Report a vulnerability

Found a vulnerability?

Send the details to the address below with “security” in the subject. Please give us time to fix it before publishing, and touch data only as far as needed to show the problem.