Security

No file data. No user data. Drive attributes only.

Crest collects S.M.A.R.T. telemetry from drive firmware. It never reads your files, directories, or application data. The agent has no access to what is stored on the drives it monitors.

TLS 1.3 in transit
AES-256 at rest
Zero file access
On-premise option

What Crest collects. What it never touches.

Collected (attribute deltas only)

  • S.M.A.R.T. attribute identifiers and raw values from drive firmware
  • Wear indicator counts (reallocated sectors, pending sectors, uncorrectable errors)
  • Power-on hours and power cycle count
  • Temperature readings (current and max over sample window)
  • Drive model string and serial number hash (SHA-256, not plaintext)
  • Agent version and host identifier (randomly generated UUID on install)

Never collected

  • File names, directory structure, or any filesystem metadata
  • File contents, database records, or application state
  • Host IP address or network configuration
  • Usernames, SSH keys, or any credential material
  • Cloud provider credentials or infrastructure identifiers
  • Any data written to or read from the drive by applications

Deployment and data residency.

Starter

Cloud-connected agent

The agent runs on your hosts and sends compressed, encrypted attribute delta payloads to Crest infrastructure in AWS ap-south-1 (Mumbai). Transit uses TLS 1.3 with certificate pinning. Payloads are signed with a per-agent key generated at install. Crest processes the telemetry in our cloud and returns risk scores to your dashboard.

  • Outbound port 443 only, no inbound required
  • Payload compression reduces bandwidth to under 2 KB per drive per hour
  • Telemetry retained for 90 days then purged
  • Building with SOC 2 controls in mind. Security posture details available on request.
Team / Fleet

Fully on-premise

The Crest risk model, ingestion pipeline, and dashboard all run inside your environment. No telemetry leaves your network. Suitable for compliance environments where data residency requirements prohibit outbound transmission of any host telemetry. Deployed via Docker Compose or Kubernetes.

  • Risk model update delivered as a signed container image
  • Dashboard accessible only within your private network
  • Fully air-gapped option: offline model update via signed file transfer
  • Retain raw telemetry locally under your data governance policies

Compliance posture.

SOC 2 Type II
Building toward SOC 2 Type II. We will publish our readiness status as controls are completed.
GDPR
No personal data collected. Agent UUID is a random identifier, not tied to a person. DPA available.
ISO 27001
Controls in scope. Formal certification roadmap in progress as the product matures.
Penetration testing
External security review planned as the product and customer base matures. Responsible disclosure policy active at [email protected].
Vulnerability disclosure
Responsible disclosure policy active. Reports to [email protected] with 90-day response window.

Security questions before you sign up?

We can walk through a technical security review with your security or compliance team before you commit. Email us with your requirements.