Trust Center

Security & trust, on your terms

Most tools ask you to trust their cloud with your most sensitive operational data. ArchiFlow is built the other way around: it runs in your environment — on-prem or air-gapped — so your network data stays with you.

Data residency by design

ArchiFlow installs on your infrastructure — on-prem or fully air-gapped. Your inventory, credentials and configs stay inside your walls.

Encrypted end to end

Encryption in transit across services, secrets kept in a protected store, and encryption at rest where your deployment provides it.

Least-privilege access

Role-based access control, scoped credential pools, and SSH command whitelisting keep operators to exactly what they need.

Auditable by default

Actions are logged with full audit trails, and configuration changes are versioned so you can see who changed what, and when.

Air-gap ready

A self-contained installer runs with zero internet access — nothing calls home, and no data leaves the environment.

Compliance-aligned

Controls mapped to SOC 2, ISO 27001 and NIST so your auditors recognize what they're looking at.

Your data doesn't tour the cloud

The difference between a cloud-only tool and ArchiFlow is where your operational data ends up.

Typical cloud SaaS

Your inventory and telemetry are uploaded and fan out across a chain of third-party clouds — hosting, databases, analytics, AI — each one a party you must trust and a place your data now lives.

ArchiFlow

Discovery, inventory, credentials and configuration stay on the infrastructure you deploy to. Air-gapped installs have no external connectivity at all — there is no cloud chain to trust.

Controls

The safeguards that protect the platform, your data, and our operations.

Product security

  • Role-based access control (RBAC) across every module
  • Scoped credential pools; secrets never shown in plaintext
  • SSH command whitelisting and rate limiting
  • Operator review and confirmation before any network change
  • Versioned configuration with rollback

Data security

  • Encryption in transit between components
  • Encryption at rest where the host environment provides it
  • Single-tenant by nature — your deployment is yours alone
  • No customer network data sent to external clouds by default
  • Full audit logging of data access

Corporate security

  • Least-privilege internal access on a need-to-know basis
  • Secure software development practices and code review
  • Dependency and vulnerability management
  • Vendor and sub-processor due diligence

Incident management

  • Defined incident response process and severity model
  • Breach notification aligned to GDPR / applicable law
  • Monitoring and alerting on the managed website
  • Coordinated disclosure channel for security researchers

Sub-processors

Transparency about who, if anyone, touches your data.

This website

A deliberately small set, by category:

  • Website hosting & content delivery
  • Transactional email
  • Privacy-respecting product analytics
  • AI provider for the optional chat assistant

A current, named list is available on request.

Your deployment

For a self-managed or air-gapped installation, there are no sub-processors touching your network data. It stays on your infrastructure, under your control. Optional cloud features are exactly that — optional, and disclosed before you enable them.

Active integrations

Live as a service

ArchiFlow already runs as a service against your stack — every system in it is an integration vector we speak to natively, from your multi-vendor network gear to inventory tools like NetBox. No single platform is the center of gravity.

Juniper logoJuniperJunos
Arista logoAristaEOS
Fortinet logoFortinetFortiOS
Palo Alto Networks logoPalo Alto NetworksPAN-OS
Cisco logoCiscoIOS · NX-OS · IOS-XR
NetBox logoNetBoxInventory & IPAM
+ 20 more platforms

Technology & AI providers

The infrastructure and AI services behind the website and optional cloud features — spanning global clouds to on-prem, air-gapped language models that never leave your environment. Every provider is vetted, access-controlled, and operated to the standards we are held to.

Amazon Web Services logoAmazon Web ServicesCloud infrastructure
Google logoGoogleCloud & technology services
Anthropic logoAnthropicClaude — AI copilot
OpenAI logoOpenAIAI model services
Ollama logoOllamaOn-prem & air-gapped LLMs (Llama)
Vercel logoVercelWebsite hosting & delivery
Docker logoDockerContainerized deployment
PostgreSQL logoPostgreSQLApplication database
Grafana logoGrafanaDashboards & metrics
Slack logoSlackTeam communication
Atlassian logoAtlassianJira & Confluence
GitHub logoGitHubSource control & CI

Security & identity

The interfaces that plug ArchiFlow into your security stack — identity, access, secrets and audit — so it fits the way you already run security.

SSO — SAML & OIDC

Sign in through your identity provider (Okta, Entra ID, Google Workspace) with SCIM-ready provisioning.

Directory & RBAC

Admin / editor / viewer roles driven by LDAP / Active Directory group membership, enforced on every write.

Encrypted credential vault

AES-256 credential pools with per-site scoping and SNMPv3 — secrets are never written to logs or shown in plaintext.

SIEM & audit export

Append-only audit trail streamable to your SIEM (syslog, Splunk, Sentinel) for full traceability.

Guarded change control

SSH command whitelisting, rate limiting, and peer-approval gates before any config reaches a device.

Air-gapped by option

Run the whole platform with zero external connectivity — fully sealed inside your enclave, with no outbound path at all.

Compliance & frameworks

Our controls are mapped to the frameworks your auditors already use.

SOC 2 aligned

Controls mapped to the SOC 2 Trust Services Criteria for security, availability and confidentiality.

ISO 27001 mapped

Information-security controls aligned to the ISO/IEC 27001 framework.

NIST-informed

Practices informed by NIST cybersecurity guidance for critical-infrastructure environments.

“Mapped” and “aligned” describe control coverage against these frameworks. Current attestation status and reports are shared under NDA on request.

AI Security

Questions we get asked

Is my data used to train AI models?

No. The in-product AI copilot runs against your own inventory inside your deployment, and website chat messages are not used to train third-party foundation models. In an air-gapped install, nothing leaves the environment at all.

Is my data accessible to other customers?

No. ArchiFlow is single-tenant by nature — it runs on your infrastructure. There is no shared multi-tenant database where another customer could reach your data.

Can ArchiFlow's AI make autonomous changes to my network?

No. The copilot is propose-and-confirm: it can suggest changes grounded in your real inventory, but nothing is applied until an operator with the right role reviews and approves it.

Where does my network and device data live?

In your environment. Discovery results, device inventory, credentials and configuration stay on the infrastructure you deploy ArchiFlow to. For air-gapped installations there is no external connectivity by design.

How is sensitive information protected?

Through encryption in transit, protected secret storage, scoped credential pools that never expose plaintext, RBAC, SSH command whitelisting, and full audit logging — layered on top of the fact that the data never has to leave your control.

Can I get your security documentation?

Yes. We share a security package — controls overview, architecture, and sub-processor detail — under NDA. Use the contact below to request it.

Need our security package?

Controls overview, architecture, sub-processor detail and current attestation status — shared under NDA. Reach the security team directly.