Security by design

Security by design, not as an option

A tool that can act on all your devices must be the hardest one to hijack. Here is every measure EPM takes, and what it prevents in practice.

01Chain of trust

The path of an order

From your security key to execution on the device, every step is checked. If a single one fails, nothing runs.

02Measures

Every measure, and what it prevents

Nothing runs without a signature

Every order sent to a device is signed and carries an expiry date. The agent checks the signature before acting and refuses everything else.

What it prevents: A forged order, or an old order replayed, is refused by the device.

Technical detailsEd25519 signature, per-order expiry

Approval with a physical security key

Risky actions require your key: installing a patch, updating an agent, rebooting a server, changing a policy.

What it prevents: A stolen password is not enough to act on your fleet.

Technical detailsYubiKey / WebAuthn

Each device's key inside the TPM chip

The key that identifies the device is stored in the TPM 2.0 chip and cannot leave it.

What it prevents: A machine can be neither cloned nor impersonated.

Technical detailsTPM 2.0, non-exportable key

Encrypted connection, authenticated both ways

Each agent and the server authenticate each other. The agent pins the server's authority.

What it prevents: Nobody can put themselves between your devices and the server.

Technical detailsTLS 1.3, mutual authentication (mTLS)

No open port on devices

The agent always calls the server, never the other way round.

What it prevents: Nothing to scan or attack on your devices from the network.

Technical detailsOutbound connection only

Console never exposed to the Internet

The console is reachable only from the networks you authorise.

What it prevents: No login page visible from the outside.

Technical detailsAccess limited to authorised networks

Sign-in with password and security key

Password plus security key, TOTP code as a fallback, single sign-on (SSO).

What it prevents: A phished credential is not enough to get into the console.

Technical detailsWebAuthn, TOTP, Keycloak SSO

Signed packages and agent

Deployed applications carry the owner's code signature. The Windows agent is Authenticode-signed and refuses any unsigned update.

What it prevents: A tampered package or a trojanised agent is never installed.

Technical detailsCode signing, Authenticode (Microsoft Azure Artifact Signing)

Four-eyes principle

In the application catalogue, an administrator cannot approve their own package.

What it prevents: No single person can push software to the whole fleet alone.

Technical detailsDraft, pending, published workflow

Agent-side red list

The agent refuses to stop vital Windows services and processes, and to disable itself.

What it prevents: Even if the console were compromised, your devices stay up and monitored.

Technical detailsEnforced by the agent

Secrets encrypted for the recipient only

Run-as account passwords are encrypted, sent encrypted for the target device only and never written to its disk.

What it prevents: A secret can be read only by the device that needs it, when it needs it.

Technical detailsAES-256-GCM

Audit log of every action

Who, what, when, on which machine, with what result.

What it prevents: You answer an audit or an incident with facts, not guesses.

Technical detailsTimestamped log

03Your data

Your data stays with you

EPM is not an online service: it is software you host yourself.

On your own server

EPM is installed on your server (Docker), inside your network. No data about your fleet goes to a third-party cloud.

Data sovereignty

An asset for your GDPR, NIS2 and DORA requirements: you know where your data is, and who accesses it.

Nightly backups

Automatic backups every night and a documented restore procedure.

Ask us your security questions

Your CISO wants to understand the signing chain, key handling or traceability? We take the time to answer.

HostCitadel