Solutions

Answer the tender without a cloud exception

NacTrack runs on your hardware, in your building. No cloud region picked by a vendor, no outbound path to justify to a security committee.

What is at stake

What a configuration actually holds

Gathered across a whole estate, it is the most complete description of your infrastructure that exists.

  • The complete addressing plan, subnet by subnet.
  • The names and roles of the sites.
  • The SNMP communities, often in clear.
  • The filtering rules and firewall zones.
  • The authentication servers and their shared keys.
  • It is exactly what an attacker would try to obtain first. Handing that set to a third party in another jurisdiction is an executive decision, not a network team decision.
The perimeter

What you can state, and what you have to declare

A compliance file asks for the exhaustive list of flows. Here it is, including the one that is not optional.

Perimeter diagram: your data stays on your side, only four flows cross the boundaryOn the left, what stays with you: configurations, inventory, topology, compliance results, credentials and reports. None of these cross the boundary. Four flows do cross it: licence validation, outbound and periodic, the only one that cannot be removed; remote support access, outbound and closed by default; the vulnerability catalogue and product updates, inbound, optional and transferable by file.Your sideCollected configurationsInventory and topologyCompliance resultsDevice access credentialsReports producedOutsideLicensing serviceVendor supportTHE PERIMETERLicence validationPeriodic, cannot be removed. Without it, read only after a long window.Support accessClosed by default. You open it, you close it.Vulnerability catalogueOptional, can be transferred by file.Product updatesTriggered by you, can be transferred by file.

Your side

  • Collected configurations
  • Inventory and topology
  • Compliance results
  • Device access credentials
  • Reports produced

Outside

  • Licensing service
  • Vendor support

THE PERIMETER

  • Licence validationoutbound, required, Periodic, cannot be removed. Without it, read only after a long window.
  • Support accessoutbound, optional, Closed by default. You open it, you close it.
  • Vulnerability catalogueinbound, optional, Optional, can be transferred by file.
  • Product updatesinbound, optional, Triggered by you, can be transferred by file.

Nothing on the left crosses. The only flow you cannot remove is licence validation, and the table below repeats it row by row.

Checkable

The questions that keep coming, and our answers

Where the data is hosted
On your hardware, on your premises. No cloud region.
Who accesses it
Your accounts. The vendor only if you open support access yourself, which you then close.
With no internet access
Collection, analysis and reporting run on your network alone. The licence has to reach our service periodically: without it the installation moves to read only after a long window, then resumes on the first successful check. Updates and security fixes come through the same channel.
If the contract ends
The appliance and the data stay with you. The reports produced belong to you.
Outbound telemetry
None by default.
Encryption at rest
LUKS2 encrypted disk on the appliance.

A demonstration against your constraint

Tell us what your framework requires, and the demonstration addresses that point.