Skip to main content10ETLabsRequest demo

Trust

What we keep. What we never take.

This is the data inventory — not the product story and not the reader IAM list. Legal text is Privacy and Terms.

What we read, store, and never touch

01Read: configuration only

Workers call list and describe APIs the reader role allows — resource settings, exposure, identity, and how AI services link to buckets and roles.

Stored

  • Asset metadata

    Type, native ID, name, region, account, category — not disk or object contents.

  • Findings

    Rule, severity, status, 10ET Score, remediation guidance, first/last seen.

  • Membership & invites

    Email, role, hashed invite tokens, optional TOTP secret (encrypted).

  • Connection secrets

    AES-256-GCM ciphertext under a key held in the platform’s secret store. No UI or API path returns plaintext to anyone, including operators.

  • Audit rows

    Sign-ins and failed passwords, logout, password resets, MFA, SSO, member invites and role changes, cloud connection changes, impersonation, and ticket creation — who, what, when, and source IP where available. Secrets are never written to the log.

  • Assistant chat history (your questions and answers)

    Ask 10ET conversations are stored in your tenant. When the AI assistant is enabled, questions and tenant context are sent to OpenAI — see Subprocessors in Privacy.

Not stored

  • Guest-OS files, disk images or volume snapshots — opt-in DeepScan reads disks inside your own account and returns findings metadata only
  • Object and blob payloads
  • Packet captures or a SIEM event lake
  • Prompts and responses inside your own AI applications and models, or your model weights
  • Your cloud write credentials — the reader role cannot write; the opt-in DeepScan role is assumed per run and can only touch snapshots and scanner VMs it tagged

Controls in this release

Read-only identity

The reader role you assume cannot mutate. Opt-in DeepScan uses a separate role limited to its own tagged snapshots and scanner VMs. Kubernetes get/list only. Production refuses TLS skip on cluster URLs.

Outbound URL gate

SIEM export, SSO issuer, and ticket bases must be https in production. Loopback, metadata, and RFC1918 are blocked except on-prem/hybrid cluster URLs.

Session hygiene

Access and refresh are httpOnly. Logout revokes the hashed refresh row. Password change revokes every refresh for that user.

Operator step-up

Impersonate requires MFA when the operator has TOTP. The session is read-only (VIEWER) and audited. No path returns plaintext secrets.

Invite safety

Accepting an invite attaches membership. It does not reset an existing user’s password.

Metrics are not public

Production /metrics requires METRICS_TOKEN. Worker health keeps liveness and hides instance hints when unauthenticated.

Tenant audit log

Owners and admins can filter and export (CSV) the organization’s audit log from Settings. Exports are themselves audited.

Retention

Findings, assets, and scan history

Kept while the cloud connection that produced them exists. Deleting a connection in the console removes its accounts, assets, findings, and scan runs immediately.

Deletion on request

Email privacy@10etlabs.com from an owner address to delete an organization and its data. We commit to completing deletion within 30 days of a verified request and confirming by email.

Audit log

Kept for the life of the organization so owners and admins can review and export it. Deleted with the organization.

Connection secrets

Deleted with the connection. Updating credentials replaces the stored ciphertext.

Vulnerability disclosure

If you believe you have found a security vulnerability in 10ETLabs, email security@10etlabs.com with steps to reproduce, the affected URL or endpoint, and the impact you observed. Our machine-readable contact is at /.well-known/security.txt. We do not run a paid bug bounty.

Scope

  • 10etlabs.com and its subdomains that we operate
  • The 10ETLabs console and API
  • Our published onboarding templates and host sensor script

Out of scope: denial-of-service or load testing, social engineering, physical attacks, spam, findings in third-party services we do not control, and reports from automated scanners without a demonstrated impact.

Safe harbor

We will not pursue legal action against good-faith research that follows this policy: test only against accounts you own or have permission to use, do not access, change, or keep other customers’ data beyond what is needed to show the issue, stop and tell us if you reach such data, avoid degrading the service, and give us reasonable time to fix the issue before disclosing it publicly.

Response targets

  • Acknowledge your report within 3 business days
  • Share our initial assessment and next steps after triage
  • Keep you updated until it is fixed, and credit you if you want to be credited

These are targets, not contractual guarantees.

Security documents

Buyers can request the following under NDA from security@10etlabs.com or through your sales contact. 10ETLabs does not currently hold any security certification or third-party attestation. The status next to each item is accurate as of this page’s last update.

DocumentStatus

Architecture & data-flow overview

Components, trust boundaries, where credentials are decrypted, and what leaves your cloud.

Available under NDA

Subprocessor list

Infrastructure, email delivery, and the optional AI assistant provider, with the data each receives.

Available under NDA

DPA template

Our data processing agreement, for your legal team’s review.

Available under NDA

Security questionnaire (CAIQ-lite)

Our answers to a CAIQ-lite style questionnaire. We will also fill in yours.

Available under NDA

Penetration test summary

No third-party penetration test has been completed yet.

Planned — contact us for status

SOC 2

We are preparing for SOC 2. We have not been audited and do not hold a SOC 2 report or any certification.

In preparation — not yet audited

Privacy · Terms

Ask about region and forward-deploy

Hosting options are a sales conversation.