Centraleyezer logo
Centraleyezer
Security

Security at Centraleyezer

We build vulnerability management software, so we hold our own platform to the same standards we help our customers meet. This page summarises how we protect customer data, manage vulnerabilities in the platform itself, and support procurement reviews.

Self-hosted by default

Customer vulnerability data never leaves your infrastructure on Enterprise and MSSP plans. The platform deploys as a Docker container into your own cloud or on-premises environment. The SaaS tier is hosted on EU-based infrastructure, capped at 10 GB per tenant.

EU data residency

For SaaS deployments, all data is stored within the European Economic Area. We do not transfer customer data outside the EEA without an adequate transfer mechanism in place.

Authentication

The platform supports SSO via SAML 2.0, OIDC (Entra ID / Azure AD), LDAP / Active Directory, and 2FA (TOTP). Local authentication uses bcrypt-hashed credentials with rate-limited login attempts.

Audit logging

Every finding-state change, risk acceptance, and user action is logged with timestamp, actor, and context. Logs are retained for the full licence term and are exportable.

Air-gap capable

Enterprise and MSSP licences support fully air-gapped deployments with no call-home requirement for licence validation, suitable for government, defence, and high-security environments.

Vulnerability disclosure

We operate a coordinated vulnerability disclosure programme. Researchers can report security issues to [email protected] and we commit to acknowledging within one business day.

Certifications & security posture

Sandline SRL, the company behind Centraleyezer, previously held an ISO/IEC 27001 certification for its information security management system. The certificate has since expired and has not yet been renewed; recertification is on our roadmap. The ISMS controls established under that certification โ€” access management, change control, incident response, supplier review, and internal audit โ€” remain in operation.

Because Centraleyezer is self-hosted first, the most important security control is architectural: on Enterprise and MSSP deployments your vulnerability data lives in your own infrastructure, under your own certifications and controls โ€” we never hold it. Procurement teams evaluating the SaaS tier can request our current questionnaire pack below.

Hosting & sub-processors

Self-hosted and air-gapped deployments involve no hosting sub-processors โ€” the platform runs entirely in your environment. For the EU SaaS tier and this website, we use the following sub-processors:

Sub-processor
Purpose
Location
Hetzner Online GmbH
SaaS platform hosting (dedicated EU data centres)
Germany & Finland (EU)
Cloudflare, Inc.
Website content delivery and edge protection (centraleyezer.io marketing site)
Global edge network

SaaS customer data is stored exclusively in Hetzner's German and Finnish data centres and does not leave the European Economic Area. Lead and analytics data from this website is processed by our own EU-hosted CRM โ€” no third-party analytics or advertising processors are used. See the Privacy Policy for details.

Reporting a vulnerability

If you discover a vulnerability in the Centraleyezer platform or website, please report it responsibly:

  • Email [email protected] with details and reproduction steps.
  • We will acknowledge within one business day and provide a tracking reference.
  • We commit to remediating critical and high-severity findings within our published SLAs.
  • Please do not exploit the vulnerability beyond what is necessary to demonstrate it, and do not access data that is not yours.

We support and acknowledge security researchers who report responsibly. A security.txt file is published at /.well-known/security.txt.

Procurement reviews

Enterprise and MSSP prospects can request our security questionnaire pack โ€” covering architecture, data flow, encryption, access controls, incident response, and sub-processors โ€” by emailing [email protected]. We typically respond within three business days.

See also: Privacy Policy, Terms of Service.

Security at Centraleyezer | Centraleyezer