Security
Last updated June 2026
How the DataStop platform and appliances are hardened. This page describes controls that are implemented today and those in progress; we do not claim certifications we have not earned.
Edge appliance
Inline bridge with hardware fail-to-wire bypass. Deterministic input parsing with fail-open to SIEM for anything ambiguous. AES-256-GCM local cache encryption with TPM-sealed keys where hardware supports it. Signed golden images.
Data reduction safety
Correlation keys are protected above all reduction categories and tokenized consistently so SIEM incident grouping is preserved. Regulated records (PCI, auth, audit, firewall) are No Touch.
Cloud platform
Bearer-token authentication, per-tenant authorization on every property and MSP route, append-only SHA-256-chained audit ledger for provisioning and critical actions, rate limiting on public endpoints.
AI-agent observation
DNS-metadata only. No payload inspection, no blocking, no throttling. Sightings are forwarded to the customer's SIEM where authorization decisions remain.
In progress
Third-party penetration test, SAST/fuzzing gate in CI, SOC 2 readiness. We will update this page as each milestone is completed.
Report a vulnerability
Email security@datastopdgm.com. We acknowledge reports within two business days and do not pursue researchers acting in good faith.