Security at Centraleyezer
We build vulnerability management software, so we hold our own platform to the same standards we help our customers meet. This page summarises how we protect customer data, manage vulnerabilities in the platform itself, and support procurement reviews.
Self-hosted by default
Customer vulnerability data never leaves your infrastructure on Enterprise and MSSP plans. The platform deploys as a Docker container into your own cloud or on-premises environment. The SaaS tier is hosted on EU-based infrastructure, capped at 10 GB per tenant.
EU data residency
For SaaS deployments, all data is stored within the European Economic Area. We do not transfer customer data outside the EEA without an adequate transfer mechanism in place.
Authentication
The platform supports SSO via SAML 2.0, OIDC (Entra ID / Azure AD), LDAP / Active Directory, and 2FA (TOTP). Local authentication uses bcrypt-hashed credentials with rate-limited login attempts.
Audit logging
Every finding-state change, risk acceptance, and user action is logged with timestamp, actor, and context. Logs are retained for the full licence term and are exportable.
Air-gap capable
Enterprise and MSSP licences support fully air-gapped deployments with no call-home requirement for licence validation, suitable for government, defence, and high-security environments.
Vulnerability disclosure
We operate a coordinated vulnerability disclosure programme. Researchers can report security issues to [email protected] and we commit to acknowledging within one business day.
Certifications & security posture
Sandline SRL, the company behind Centraleyezer, previously held an ISO/IEC 27001 certification for its information security management system. The certificate has since expired and has not yet been renewed; recertification is on our roadmap. The ISMS controls established under that certification โ access management, change control, incident response, supplier review, and internal audit โ remain in operation.
Because Centraleyezer is self-hosted first, the most important security control is architectural: on Enterprise and MSSP deployments your vulnerability data lives in your own infrastructure, under your own certifications and controls โ we never hold it. Procurement teams evaluating the SaaS tier can request our current questionnaire pack below.
Hosting & sub-processors
Self-hosted and air-gapped deployments involve no hosting sub-processors โ the platform runs entirely in your environment. For the EU SaaS tier and this website, we use the following sub-processors:
SaaS customer data is stored exclusively in Hetzner's German and Finnish data centres and does not leave the European Economic Area. Lead and analytics data from this website is processed by our own EU-hosted CRM โ no third-party analytics or advertising processors are used. See the Privacy Policy for details.
Reporting a vulnerability
If you discover a vulnerability in the Centraleyezer platform or website, please report it responsibly:
- Email [email protected] with details and reproduction steps.
- We will acknowledge within one business day and provide a tracking reference.
- We commit to remediating critical and high-severity findings within our published SLAs.
- Please do not exploit the vulnerability beyond what is necessary to demonstrate it, and do not access data that is not yours.
We support and acknowledge security researchers who report responsibly. A security.txt file is published at /.well-known/security.txt.
Procurement reviews
Enterprise and MSSP prospects can request our security questionnaire pack โ covering architecture, data flow, encryption, access controls, incident response, and sub-processors โ by emailing [email protected]. We typically respond within three business days.
See also: Privacy Policy, Terms of Service.