Where your data lives
Customer telemetry is stored in the region you choose (US, UK or EU) and does not leave it. Hosted on IONOS, Microsoft Azure and Google Cloud.
Least-privilege access
Analysts use named accounts with phishing-resistant MFA, just-in-time elevation and full session logging. No shared credentials.
Scoped response permissions
API permissions are limited to the actions in your response-authority agreement. You can revoke them at any time.
Encryption
TLS 1.2+ in transit and AES-256 at rest, with keys managed by our cloud provider’s key service.
Retention and exit
Telemetry is kept for 90 days by default. Data linked to a major incident is retained for 13 months to support investigation, insurance and regulatory needs. On exit, you get a full export in open formats and we delete your data within 30 days.
We watch ourselves too
Our own environment is monitored by Pulse, with the same detections and SLAs our customers get.