Trust Center

Security claims should come with evidence and limits.

This page reads our shipped-capability ledger and a public projection of reviewed, sanitized operational proof. Roadmap work and customer-identifying records never belong here.

Architecture and boundaries

Designed for managed operations, without hiding scope.

The control plane coordinates tenant-scoped work; endpoint and cloud collectors report the evidence their platform can actually produce.

Architecture

Separated evidence and action

Collectors produce evidence, policy gates decide what is permitted, and response records the outcome. Advisory scoring cannot silently grant execution permission.

Tenant isolation

Scoped at every data boundary

Operational records are tenant-owned and accessed through tenant-scoped stores and guards. The public proof feed is a separate sanitized projection, not a window into tenant data.

Update safety

Rings with a halt path

Customer-controlled Canary and Broad rings can stop endpoint-agent rollout when rollback regressions cross the configured safety threshold.

Security operations

Missing signals stay missing

Operational and compliance views derive from current telemetry. An unavailable collector is reported as not assessed instead of being converted into a passing result.

Optional service

Posture and image evidence

Cloud posture findings, provider connections, immutable image evidence and SBOM status are available only when the private CloudSecurity service is configured and its scanners report ready. Otherwise this scope is unavailable, not a shipped endpoint capability or a clean result. Runtime workload protection and a complete CNAPP are not claimed.

Shipped-capability ledger

Claims rendered from the source of truth.

This list is loaded from /security-capabilities.json. The server sends the browser only entries already marked shipped.

Loading shipped capabilitiesReading the public claims ledger.

Reviewed public proof

Operational outcomes, sanitized before publication.

Proof covers detection, response, recovery, rollout and onboarding exercises. Metrics appear with their unit and evidence reference; customer names, tenant identifiers and unpublished records do not.

Loading reviewed proofReading the sanitized public projection.

Platform support and limitations

Support means the active sensor reports it.

Supported today

  • Windows and Linux provide the broadest endpoint sensing coverage.
  • macOS endpoint capabilities are listed per control as supported or limited.
  • Cloud-native controls are called out separately from endpoint controls.
  • Every capability row below carries its own platform support state.

Not implied

  • Limited support does not mean feature parity.
  • Unsupported cloud scope is not converted into endpoint coverage.
  • Lab and unfinished work is not a shipped claim.
  • No public proof record identifies a customer or tenant.

Evaluate CloudCastle

Start small and inspect the evidence.

Choose explicit dates, review the proof cadence with your team, and decide whether the observed outcomes justify expansion.