Security

Last updated June 2026

How the DataStop platform and appliances are hardened. This page describes controls that are implemented today and those in progress; we do not claim certifications we have not earned.

Edge appliance

Inline bridge with hardware fail-to-wire bypass. Deterministic input parsing with fail-open to SIEM for anything ambiguous. AES-256-GCM local cache encryption with TPM-sealed keys where hardware supports it. Signed golden images.

Data reduction safety

Correlation keys are protected above all reduction categories and tokenized consistently so SIEM incident grouping is preserved. Regulated records (PCI, auth, audit, firewall) are No Touch.

Cloud platform

Bearer-token authentication, per-tenant authorization on every property and MSP route, append-only SHA-256-chained audit ledger for provisioning and critical actions, rate limiting on public endpoints.

AI-agent observation

DNS-metadata only. No payload inspection, no blocking, no throttling. Sightings are forwarded to the customer's SIEM where authorization decisions remain.

In progress

Third-party penetration test, SAST/fuzzing gate in CI, SOC 2 readiness. We will update this page as each milestone is completed.

Report a vulnerability

Email security@datastopdgm.com. We acknowledge reports within two business days and do not pursue researchers acting in good faith.