Why NacTrack

The inventory is a target. Here is what guards it.

One box ends up holding every configuration and every credential on the estate. LUKS2 on the disk, credentials encrypted at rest, tenant isolation at the data layer, and further down the list of what we do not claim.

The measures that matter

Disk encryption

The appliance encrypts its disk with LUKS2. A disk removed from the machine yields nothing.

Access secrets

Device credentials are encrypted at rest with a key specific to the installation, and never displayed in clear.

Read only

Collection needs read access only. NacTrack does not push configuration to your devices.

Tenant isolation

Every query is filtered by tenant at the data layer, not only in the interface.

Signed licences

Entitlements are carried by a cryptographically signed licence, verified locally.

Traceability

Administrative actions are logged, with author and timestamp.

What has to be got through

What someone actually holds, at each stage

The right hand column is the only one that matters. A diagram that drew only the barriers would be a brochure.

Three nested barriers around the estate configurations and credentialsAt the centre, what the machine ends up holding: the estate's configurations and credentials. Around it, three nested barriers. The disk, encrypted with LUKS2, yields nothing once taken out of the machine. On a running machine, device credentials remain encrypted at rest and separately, but the collected configurations are stored as captured. An application account opens only what its role allows, and only the tenants it is attached to.THE DISKA disk taken out of the machine: nothingusable, it is encrypted with LUKS2.THE RUNNING MACHINESystem access: device credentials stayencrypted at rest, separately. The collectedconfigurations do not: they are stored ascaptured.AN APPLICATION ACCOUNTWhat its role allows, and only the tenantsit is attached to.Estate configurations and credentialswhat this machine ends up holding
  • THE DISKA disk taken out of the machine: nothing usable, it is encrypted with LUKS2.
  • THE RUNNING MACHINESystem access: device credentials stay encrypted at rest, separately. The collected configurations do not: they are stored as captured.
  • AN APPLICATION ACCOUNTWhat its role allows, and only the tenants it is attached to.
  • Estate configurations and credentialswhat this machine ends up holding

These are nested barriers and not steps: all of them have to be got through, and the list of what we do not claim is directly below.

The limits

What we do not claim

  • NacTrack is certified by no third party body today. We would rather write that than display a logo borrowed from a framework we are not assessed against.
  • An independent security audit of the product is a legitimate request at this purchase level. We handle it case by case as part of the evaluation.
  • Nothing listed here replaces your own controls: separating the management network, restricting access to the appliance and managing accounts remain on your side.
  • Collection credentials are encrypted at rest, but an over permissive collection account is still an over permissive account. Give it the minimum.
  • The configurations we collect are kept as captured, not redacted. A configuration often contains its own secrets, a TACACS key or an SNMP community, and anyone with system access on the appliance reads what they hold. Restricting access to the appliance is the control that matters here, not disk encryption.

A precise technical question?