FAQ
Questions we answer on a first call
Short answers. Longer operating detail is on How it works; data handling is on Trust; commercials are on Pricing.
- Is 10ETLabs agentless?
- Yes, for cloud connections. You assume a reader role, Kubernetes get/list, or a VPS token you already control. Nothing installs in the guest OS unless you choose the optional host sensor for VPS hosts, and nothing runs in your clusters unless you install the optional Kubernetes runtime sensor or admission webhook. Opt-in DeepScan is agentless too: it scans disk snapshots in your own account.
- Do you write back to our clouds?
- Not by default. Every connection is read-only. Fixes are code you review: findings for the top rules come with a generated Terraform, CloudFormation, Azure CLI / Bicep, gcloud or Kubernetes patch you copy, download, or (if you turn on the separate write opt-in for a source-control connection) receive as a pull request on a new branch. Only if you deploy a separate remediator role, with its own identity and only the exact write permissions of each supported fix, can an Owner or Admin approve one-click changes. Each one shows before → after, is confirmed by re-reading the resource, is fully audited, and can be rolled back where the change is reversible.
- What data do you keep after a scan?
- Asset metadata, findings, membership, encrypted connection secrets, and Ask 10ET chat history. Not disks, object bodies, or packet captures. See Trust for the inventory.
- What does “from code to cloud” mean here?
- Paste Terraform, CloudFormation, ARM, or Kubernetes YAML in the console — or run the 10et CLI on every pull request in GitHub Actions, GitLab CI, Azure Pipelines, or Bitbucket Pipelines — and ten built-in pattern rules flag public, open, wildcard, unencrypted, privileged, and AI-infrastructure settings. They are line-level pattern rules, not a full policy engine. After you connect, the same risk classes are checked on live inventory.
- What exactly do you check on AI services?
- On AWS: SageMaker notebooks, endpoints, and models, and Bedrock custom models, agents, knowledge bases, guardrails, and invocation logging, linked to the buckets and roles behind them to build attack paths. On Azure: Azure OpenAI and AI Services deployments and their content filters, AI Foundry hubs, projects and data connections, Azure ML online endpoints with the model, training job, container image and managed identity behind each, compute instances, and AI Search. On Google Cloud: Vertex AI endpoints, models, datasets, training and tuning jobs, Vector Search, RAG corpora, Agent Engine, and Workbench instances, linked to the buckets and service accounts behind them. We read configuration only — never prompts, responses, or model weights — and we do not do prompt-injection testing.
- Do you test for prompt injection?
- You do, with our open-source 10et-ai-test CLI. It runs on your machine or in your CI with your own model credentials and tests for prompt injection, system-prompt and data leakage, jailbreaks, tool abuse, unsafe output and runaway token use, using canary tokens rather than harmful content. Prompts, responses and credentials never reach 10ETLabs. If you add --upload, only the pass/fail verdict per test is sent, and failures on an endpoint you map to an AI asset appear as findings in the console.
- How is an AI attack path different from a finding?
- A finding is one misconfiguration. A path chains them with links we read from your cloud — for example, a public bucket that a live endpoint loads its model from, or an internet-facing notebook whose role is account admin. If we could not read a hop, we do not show the path.
- What do you read from Azure Entra ID, and what permissions does it need?
- With the read-only Microsoft Graph application permissions Directory.Read.All and RoleManagement.Read.Directory (plus optional Policy.Read.All and AuditLog.Read.All, all granted with admin consent): users and guests, groups, service principals, managed identities, app registrations with their credential types and expiry dates (never secret values), directory roles including PIM eligible versus active, Conditional Access, and last sign-in dates. Reader on each subscription already covers Azure role assignments, role definitions and deny assignments, which we resolve into effective permissions per principal. If a permission is missing or a feature needs an Entra ID P1/P2 license you do not have, that area is shown as a coverage gap, never as a pass or a finding.
- Do you inventory CVEs inside every VM?
- If you opt in to DeepScan. It snapshots EC2, Azure VM and GCE disks and scans them with a short-lived scanner in your own account, then deletes the snapshots; only findings metadata (package, CVE, fixed version, secret type and path — never values) comes back. Without DeepScan, package CVEs appear on hosts with the optional host sensor.
- Can we run it in our own cloud?
- Yes. The same product installs in your account with a Helm chart or on a single VM, with your Postgres and Redis. Your cloud metadata and the key that encrypts your credentials stay with you, and the license is checked offline with no phone-home. Ask 10ET stays off unless you add your own OpenAI key. See Run it in your cloud.
- Can we self-serve checkout?
- No. Billing is sales-led. Production tenants are invite-only. Request a walkthrough; there is no Stripe in this release.
- Who can open a customer tenant from 10ETLabs?
- A platform operator, after MFA when enabled, as read-only VIEWER. The session is audited. Your cloud secrets are encrypted at rest with AES-256-GCM using a key held in the platform’s secret store, and there is no UI or API path that returns plaintext credentials to anyone, including our operators. The credentials are read-only roles you can revoke at any time.
- Do you replace our SIEM?
- No. The Detection page is a manual export of findings as JSON to a URL you control, plus CloudTrail posture rules (is logging on, multi-region, capturing management events). We do not analyze event logs, run a detection lake, or do real-time threat detection.
- Does the Ask 10ET assistant send our data to a third party?
- Only when the AI assistant is enabled for your tenant. Then your question and relevant tenant context — finding titles, severities, resource names, remediation text, and attack-path summaries — are sent to OpenAI. Secrets are never sent. OpenAI’s API data-usage policy states API data is not used to train models by default. Chat history is stored in your tenant. See Subprocessors in Privacy.
- Where does SSO fit?
- Optional OIDC for the tenant. Membership still requires an invite. ID tokens are verified against the issuer JWKS; unsigned tokens are rejected.
Still open? Contact or book a walkthrough.