Why NacTrack

Your configurations never leave the building

NacTrack installs on your own infrastructure. Configurations, credentials and reports stay with you, and the table below says exactly what crosses the perimeter, and when.

The perimeter

What crosses, and what does not

Six flows exist in total. Five are optional or triggered by you. The sixth is not, and it is on the drawing like the rest.

Perimeter diagram: your data stays on your side, only four flows cross the boundaryOn the left, what stays with you: configurations, inventory, topology, compliance results, credentials and reports. None of these cross the boundary. Four flows do cross it: licence validation, outbound and periodic, the only one that cannot be removed; remote support access, outbound and closed by default; the vulnerability catalogue and product updates, inbound, optional and transferable by file.Your sideCollected configurationsInventory and topologyCompliance resultsDevice access credentialsReports producedOutsideLicensing serviceVendor supportTHE PERIMETERLicence validationPeriodic, cannot be removed. Without it, read only after a long window.Support accessClosed by default. You open it, you close it.Vulnerability catalogueOptional, can be transferred by file.Product updatesTriggered by you, can be transferred by file.

Your side

  • Collected configurations
  • Inventory and topology
  • Compliance results
  • Device access credentials
  • Reports produced

Outside

  • Licensing service
  • Vendor support

THE PERIMETER

  • Licence validationoutbound, required, Periodic, cannot be removed. Without it, read only after a long window.
  • Support accessoutbound, optional, Closed by default. You open it, you close it.
  • Vulnerability catalogueinbound, optional, Optional, can be transferred by file.
  • Product updatesinbound, optional, Triggered by you, can be transferred by file.

Nothing on the left crosses. The only flow you cannot remove is licence validation, and the table below repeats it row by row.

What crosses the perimeter, and when

FlowOutbound?Triggered byCan be removed
Collected configurationsnevernothingnot applicable
Inventory and resultsnevernothingnot applicable
Usage telemetrynonenothingnot applicable
Vulnerability catalogueinboundyou, or a scheduled taskyes, transfer by file
Product updatesinboundyouyes, transfer by file
Licence validationperiodicthe productno, read only without it
Remote support accesson demandyou aloneyes, closed by default

No row in this table sends a configuration, an inventory or an evaluation result outward. The only outbound flows are licence validation and remote support access, closed by default and opened by you. The access can be removed; licence validation cannot: deprived of it long enough, the installation moves to read only.

Ask us the question that blocks you

If your framework imposes a specific constraint, tell us before the demonstration.