Trust
What we keep. What we never take.
This is the data inventory — not the product story and not the reader IAM list. Legal text is Privacy and Terms.
What we read, store, and never touch
01Read: configuration only
Workers call list and describe APIs the reader role allows — resource settings, exposure, identity, and how AI services link to buckets and roles.
Stored
Asset metadata
Type, native ID, name, region, account, category — not disk or object contents.
Findings
Rule, severity, status, 10ET Score, remediation guidance, first/last seen.
Membership & invites
Email, role, hashed invite tokens, optional TOTP secret (encrypted).
Connection secrets
AES-256-GCM ciphertext under a key held in the platform’s secret store. No UI or API path returns plaintext to anyone, including operators.
Audit rows
Sign-ins and failed passwords, logout, password resets, MFA, SSO, member invites and role changes, cloud connection changes, impersonation, and ticket creation — who, what, when, and source IP where available. Secrets are never written to the log.
Assistant chat history (your questions and answers)
Ask 10ET conversations are stored in your tenant. When the AI assistant is enabled, questions and tenant context are sent to OpenAI — see Subprocessors in Privacy.
Not stored
- Guest-OS files, disk images or volume snapshots — opt-in DeepScan reads disks inside your own account and returns findings metadata only
- Object and blob payloads
- Packet captures or a SIEM event lake
- Prompts and responses inside your own AI applications and models, or your model weights
- Your cloud write credentials — the reader role cannot write; the opt-in DeepScan role is assumed per run and can only touch snapshots and scanner VMs it tagged
Controls in this release
Read-only identity
The reader role you assume cannot mutate. Opt-in DeepScan uses a separate role limited to its own tagged snapshots and scanner VMs. Kubernetes get/list only. Production refuses TLS skip on cluster URLs.
Outbound URL gate
SIEM export, SSO issuer, and ticket bases must be https in production. Loopback, metadata, and RFC1918 are blocked except on-prem/hybrid cluster URLs.
Session hygiene
Access and refresh are httpOnly. Logout revokes the hashed refresh row. Password change revokes every refresh for that user.
Operator step-up
Impersonate requires MFA when the operator has TOTP. The session is read-only (VIEWER) and audited. No path returns plaintext secrets.
Invite safety
Accepting an invite attaches membership. It does not reset an existing user’s password.
Metrics are not public
Production /metrics requires METRICS_TOKEN. Worker health keeps liveness and hides instance hints when unauthenticated.
Tenant audit log
Owners and admins can filter and export (CSV) the organization’s audit log from Settings. Exports are themselves audited.
Retention
Findings, assets, and scan history
Kept while the cloud connection that produced them exists. Deleting a connection in the console removes its accounts, assets, findings, and scan runs immediately.
Deletion on request
Email privacy@10etlabs.com from an owner address to delete an organization and its data. We commit to completing deletion within 30 days of a verified request and confirming by email.
Audit log
Kept for the life of the organization so owners and admins can review and export it. Deleted with the organization.
Connection secrets
Deleted with the connection. Updating credentials replaces the stored ciphertext.
Vulnerability disclosure
If you believe you have found a security vulnerability in 10ETLabs, email security@10etlabs.com with steps to reproduce, the affected URL or endpoint, and the impact you observed. Our machine-readable contact is at /.well-known/security.txt. We do not run a paid bug bounty.
Scope
- 10etlabs.com and its subdomains that we operate
- The 10ETLabs console and API
- Our published onboarding templates and host sensor script
Out of scope: denial-of-service or load testing, social engineering, physical attacks, spam, findings in third-party services we do not control, and reports from automated scanners without a demonstrated impact.
Safe harbor
We will not pursue legal action against good-faith research that follows this policy: test only against accounts you own or have permission to use, do not access, change, or keep other customers’ data beyond what is needed to show the issue, stop and tell us if you reach such data, avoid degrading the service, and give us reasonable time to fix the issue before disclosing it publicly.
Response targets
- Acknowledge your report within 3 business days
- Share our initial assessment and next steps after triage
- Keep you updated until it is fixed, and credit you if you want to be credited
These are targets, not contractual guarantees.
Security documents
Buyers can request the following under NDA from security@10etlabs.com or through your sales contact. 10ETLabs does not currently hold any security certification or third-party attestation. The status next to each item is accurate as of this page’s last update.
| Document | Status |
|---|---|
Architecture & data-flow overview Components, trust boundaries, where credentials are decrypted, and what leaves your cloud. | Available under NDA |
Subprocessor list Infrastructure, email delivery, and the optional AI assistant provider, with the data each receives. | Available under NDA |
DPA template Our data processing agreement, for your legal team’s review. | Available under NDA |
Security questionnaire (CAIQ-lite) Our answers to a CAIQ-lite style questionnaire. We will also fill in yours. | Available under NDA |
Penetration test summary No third-party penetration test has been completed yet. | Planned — contact us for status |
SOC 2 We are preparing for SOC 2. We have not been audited and do not hold a SOC 2 report or any certification. | In preparation — not yet audited |