Cette page n'est disponible pour l'instant qu'en anglais.
Security
Last updated: March 2026 · Version: 1.0 · Controller / Processor: TriStiX S.L.
1. Policy Statement
Security is a first-class product property at NetSenX, not an afterthought. We commit to:
- Process Personal Data exclusively within the European Economic Area, with EU-region encryption at rest and TLS 1.3 in transit.
- Operate the platform under a documented incident-response procedure with a 72-hour breach-notification SLA to controllers and supervisory authorities (GDPR Art. 33).
- Welcome good-faith security research and never pursue legal action for in-scope, in-good faith disclosures (see Responsible Disclosure).
- Publish a machine-readable security contact under /.well-known/security.txt per RFC 9116.
2. Security Controls Summary
| Area | Control |
|---|---|
| Encryption at rest | AES-256 (EU database provider) |
| Encryption in transit | TLS 1.3 only; HSTS preload enabled |
| Key management | Cloud KMS for managed keys; BYOK with FIPS 140-2 Level 3 HSM for Enterprise tier |
| Data residency | EU-only processing; sub-processors operate in EU regions |
| Audit trail | Tamper-evident SHA-256 hash chain for every administrative action |
| Access control | RBAC (Admin / Analyst / Viewer / Auditor); MFA mandatory for Admin role |
| Vulnerability management | SAST, dependency scanning, supply-chain signing; 72h patch SLA for critical CVEs |
| Backups | Daily automated, 30-day retention, EU region, encrypted at rest |
| Limited protocol inspection | The agent works mainly from flow metadata and reads only a few protocol fields on the monitored host (TLS server name, DNS answers, industrial control commands). It never decrypts encrypted connections, and in its standard configuration no packet content is sent. Server names are sent only in a random sample of about 1 in 1,000 flow records. |
3. Vulnerability Disclosure
We operate a Coordinated Vulnerability Disclosure (CVD) programme. For full details including scope, safe harbor, SLA, and disclosure timelines, see Responsible Disclosure.
Researchers can locate our security contacts at any time via the RFC 9116 file at /.well-known/security.txt.
4. Bug Bounty
NetSenX’s bug-bounty programme is hosted on Intigriti and is in setup ahead of V1b. The programme will open to invited researchers first, then to the public, with bounty bands commensurate with severity (CVSS v4.0). In the interim, please use the email and PGP channels described below; valid in-scope reports submitted during the soft-launch phase will be eligible for retroactive bounty consideration.
5. PGP Key
A PGP public key for [email protected] is available on request. The fingerprint will be published here and on the WKD endpoint once the key is rotated for V1b.
6. Incident Response
- Detection: 24×7 alerting on platform-wide health and security telemetry.
- Containment: a documented runbook covers credential rotation, tenant isolation review, and forensic preservation.
- Notification: affected customers are notified within 24 hours of confirmed breach (DPA Section 9); regulatory authorities within 72 hours (GDPR Art. 33).
- Post-incident: root-cause analysis is published privately to the affected customers within 14 days, with remediation timelines.
7. Compliance & Certifications
See /compliance for the current status of our compliance roadmap (NIS2, GDPR, ISO 27001, SOC 2 Type II).
8. Contact
- Security reports: [email protected]
- PGP key: on request from the same address
- Machine-readable contact: /.well-known/security.txt
- Coordinated Disclosure policy: /responsible-disclosure