
Security
How Tessarac protects your data
Tessarac is the system you trust with every other system’s credentials. We hold ourselves to the standard our customers will be audited against — and publish exactly where we are on each framework so you can plan, not guess.
Security posture
What we do on every deployment. Federal adds stricter defaults on top (FIPS-validated crypto enforced, STIG-hardened base images, 24-hour critical-patch SLA).
End-to-end agent envelope encryption
Every Sentinel agent payload is wrapped at the agent with a per-event AES-256-GCM data encryption key, then wrapped again with the per-tenant ECDSA P-384 trust anchor. Even our load balancers can't read it — they're a TLS-stripping pass-through. The trust boundary is the agent on your host, not our cloud account.
Bring (or hold) your own keys
Customer-managed keys via every major cloud key-management system or HashiCorp Vault. HYOK (hold your own key) is available with the Dedicated HSM add-on or on Federal — root keys live inside your own HSM that we never see. The agent ↔ control plane envelope decrypts inside your boundary.
Hardware-bound agent identity
Sentinel's signing key is generated inside the host's TPM, Secure Enclave, or WPCP — private half never leaves hardware. Defeats the credential-extraction class of attack against the agent. There is no agent token sitting in a file to steal.
IPv6-native control + data plane
Every endpoint listens on dual-stack [::]:port, AAAA records published alongside A records, cordon rules emit both IPv4 and IPv6 ACLs. Satisfies OMB M-21-07 and the FedRAMP IPv6 capability requirement out of the box.
Ephemeral sandbox infrastructure
Suspect file gets detonated in a sandbox spun up in your tenant's compliance region, captured indicators land in the audit log, sandbox is torn down. Pay-per-detonation, near-zero idle cost, no cross-tenant data exposure.
Tenant isolation by default
Every tenant runs inside a strict logical boundary with cross-tenant access blocked at the database RLS layer. Self-host gives you a physically isolated deployment; the Federal plan gives you a sovereign one.
Hardware-backed admin access
Tessarac staff access production only with a phishing-resistant hardware key (FIDO2 / smart card), plus role-based, time-bound elevation. No long-lived production credentials exist.
Signed releases and SBOM
Every release ships with a Sigstore-signed container image, a reproducible-build attestation, and a software bill of materials in SPDX and CycloneDX. Verify what you run before you run it.
Continuous scanning
Static analysis, dependency-vulnerability scanning, and infrastructure-as-code review run on every commit. Patch SLAs: Critical = 2 business days on Paid, 24 hours on Federal; High = 10 business days on both.
Compliance status
Honest snapshot of where each framework stands today. We update this table when status changes, not when an audit closes.
| Framework | Status | Notes |
|---|---|---|
| SOC 2 Type 2 | In flight | Phase 1 — observation period open; report expected end of Phase 2. Going straight to Type 2 (no Type 1 step). |
| HIPAA | Ready | Business Associate Agreement available on the Paid plan. |
| PCI-DSS v4 | Ready | Reference architecture published for cardholder-data login deployments. |
| FedRAMP High | Targeted | Phase 3 — 3PAO assessment underway; pursuing Agency Authorization with a sponsoring agency. Federal plan deploys in our sovereign US-only environment on FedRAMP-authorized infrastructure, or fully on-premises. Going straight to High (no Moderate step). |
| DoD IL5 | Roadmap | Phase 4 — Federal plan only, sovereign US-only or on-premises. Inherits FedRAMP High baseline. |
| CMMC 2.0 L2 | Roadmap | Phase 4 — for defense industrial base customers. |
| GDPR | Ready | Data Processing Agreement available; EU data residency on Enterprise and Federal. |
“Ready” means the controls and contractual artifacts are in place today. “In flight” means an audit is actively underway. “Targeted” means scheduled for the named phase. “Roadmap” means committed but not yet scheduled.
Reporting vulnerabilities
We rely on the security community. If you’ve found something, get in touch — we’ll respond fast and we don’t pursue good-faith researchers.
- Where to report
- security@tessarac.com
PGP key published at/.well-known/security.txt - First response
- Within 1 business day.
- Triage
- CVSS 9.0+ within 24 hours. CVSS 7.0+ within 3 days.
- Patch SLA
- Critical: 24 hours (Federal) / 2 business days (Paid). High: 10 business days (both, tighter on Federal by contract).
- Safe harbor
- Good-faith research that respects user privacy and doesn’t disrupt service is welcomed and protected from legal action under our coordinated-disclosure policy.
Sub-processors
The current sub-processor list (cloud providers, payment processors, observability tooling) is published in our trust portal and updated 30 days before any change. Customers under contract are notified by email.
Open source & licensing
Tessarac is open-core. The Community edition is source-available under the Tessarac Community License. Paid and Federal deployments are licensed under a standard commercial agreement that includes IP indemnification.