Abstract layered shield illustration in indigo and violet.

Security

How Tessarac protects your data

Tessarac is the system you trust with every other system’s credentials. We hold ourselves to the standard our customers will be audited against — and publish exactly where we are on each framework so you can plan, not guess.

Security posture

What we do on every deployment. Federal adds stricter defaults on top (FIPS-validated crypto enforced, STIG-hardened base images, 24-hour critical-patch SLA).

  • End-to-end agent envelope encryption

    Every Sentinel agent payload is wrapped at the agent with a per-event AES-256-GCM data encryption key, then wrapped again with the per-tenant ECDSA P-384 trust anchor. Even our load balancers can't read it — they're a TLS-stripping pass-through. The trust boundary is the agent on your host, not our cloud account.

  • Bring (or hold) your own keys

    Customer-managed keys via every major cloud key-management system or HashiCorp Vault. HYOK (hold your own key) is available with the Dedicated HSM add-on or on Federal — root keys live inside your own HSM that we never see. The agent ↔ control plane envelope decrypts inside your boundary.

  • Hardware-bound agent identity

    Sentinel's signing key is generated inside the host's TPM, Secure Enclave, or WPCP — private half never leaves hardware. Defeats the credential-extraction class of attack against the agent. There is no agent token sitting in a file to steal.

  • IPv6-native control + data plane

    Every endpoint listens on dual-stack [::]:port, AAAA records published alongside A records, cordon rules emit both IPv4 and IPv6 ACLs. Satisfies OMB M-21-07 and the FedRAMP IPv6 capability requirement out of the box.

  • Ephemeral sandbox infrastructure

    Suspect file gets detonated in a sandbox spun up in your tenant's compliance region, captured indicators land in the audit log, sandbox is torn down. Pay-per-detonation, near-zero idle cost, no cross-tenant data exposure.

  • Tenant isolation by default

    Every tenant runs inside a strict logical boundary with cross-tenant access blocked at the database RLS layer. Self-host gives you a physically isolated deployment; the Federal plan gives you a sovereign one.

  • Hardware-backed admin access

    Tessarac staff access production only with a phishing-resistant hardware key (FIDO2 / smart card), plus role-based, time-bound elevation. No long-lived production credentials exist.

  • Signed releases and SBOM

    Every release ships with a Sigstore-signed container image, a reproducible-build attestation, and a software bill of materials in SPDX and CycloneDX. Verify what you run before you run it.

  • Continuous scanning

    Static analysis, dependency-vulnerability scanning, and infrastructure-as-code review run on every commit. Patch SLAs: Critical = 2 business days on Paid, 24 hours on Federal; High = 10 business days on both.

Compliance status

Honest snapshot of where each framework stands today. We update this table when status changes, not when an audit closes.

FrameworkStatusNotes
SOC 2 Type 2In flightPhase 1 — observation period open; report expected end of Phase 2. Going straight to Type 2 (no Type 1 step).
HIPAAReadyBusiness Associate Agreement available on the Paid plan.
PCI-DSS v4ReadyReference architecture published for cardholder-data login deployments.
FedRAMP HighTargetedPhase 3 — 3PAO assessment underway; pursuing Agency Authorization with a sponsoring agency. Federal plan deploys in our sovereign US-only environment on FedRAMP-authorized infrastructure, or fully on-premises. Going straight to High (no Moderate step).
DoD IL5RoadmapPhase 4 — Federal plan only, sovereign US-only or on-premises. Inherits FedRAMP High baseline.
CMMC 2.0 L2RoadmapPhase 4 — for defense industrial base customers.
GDPRReadyData Processing Agreement available; EU data residency on Enterprise and Federal.

“Ready” means the controls and contractual artifacts are in place today. “In flight” means an audit is actively underway. “Targeted” means scheduled for the named phase. “Roadmap” means committed but not yet scheduled.

Reporting vulnerabilities

We rely on the security community. If you’ve found something, get in touch — we’ll respond fast and we don’t pursue good-faith researchers.

Where to report
security@tessarac.com
PGP key published at /.well-known/security.txt
First response
Within 1 business day.
Triage
CVSS 9.0+ within 24 hours. CVSS 7.0+ within 3 days.
Patch SLA
Critical: 24 hours (Federal) / 2 business days (Paid). High: 10 business days (both, tighter on Federal by contract).
Safe harbor
Good-faith research that respects user privacy and doesn’t disrupt service is welcomed and protected from legal action under our coordinated-disclosure policy.

Sub-processors

The current sub-processor list (cloud providers, payment processors, observability tooling) is published in our trust portal and updated 30 days before any change. Customers under contract are notified by email.

Open source & licensing

Tessarac is open-core. The Community edition is source-available under the Tessarac Community License. Paid and Federal deployments are licensed under a standard commercial agreement that includes IP indemnification.