Platform security

How the platform that monitors you is itself secured

A managed security platform concentrates exactly the information an attacker would most like to have. It is a high-value target by construction, and it should be built and questioned accordingly.

If you engage a managed security service, that service ends up holding a map of your network, the state of your defences, and a record of where your gaps are. Asking how that platform is protected is not an awkward question. It is the correct one, and any vendor that treats it as an obstacle is telling you something.

What follows is how Vanguard is built and operated. Where a control is a design decision rather than a certification, we say so - and where we hold no certification, we say that too.

Tenant isolation

  • Each organisation is a separate tenant with its own agent group and data separation, established at onboarding rather than retrofitted.
  • Access rules restrict every user to their own organisation, enforced at the data layer rather than hidden in the interface.
  • Isolation is verified by authenticating as a tenant user, attempting a cross-tenant read, and asserting that it fails.
  • A dedicated detection fires if any request or query crosses a tenant boundary.

Access control

  • Multi-factor authentication on administrative and analyst access.
  • Analysts reach only the organisations they are assigned to; there is no default access to everything.
  • Administrative accounts are separate from day-to-day accounts, so routine work does not carry privileged rights.
  • Administrative interfaces are reachable only over private networking or VPN, never directly from the internet.
  • Access is logged and retained, including access by our own staff.

Data protection

  • Transport encryption on every connection, between agents and the platform and between platform components.
  • Encryption at rest for stored telemetry and backups.
  • Retention is agreed per organisation and enforced by lifecycle policy, so data is not held indefinitely by default.
  • Vanguard collects security telemetry - process, authentication, network and integrity events. It is not a content inspection product and does not read document contents or email bodies.
  • What is collected is defined at onboarding and can be narrowed where specific systems require it.

Infrastructure security

  • Components are bound to loopback or private networks and reached through an authenticated reverse proxy.
  • Only the services that must be publicly reachable are exposed, and exposure is verified by test rather than assumed from configuration.
  • Host hardening includes key-based authentication only, automatic security updates, and both rate-based and reputation-based blocking of hostile traffic.
  • The platform monitors its own infrastructure, and blocking rules are checked with a control case so a broken allow-list cannot pass as working.

Operational assurance

  • A heartbeat checks every component on a short cycle for both liveness and recent ingestion - a running service with a stalled feed detects nothing.
  • Log source silence raises an alert within one cycle rather than being discovered during an investigation.
  • Certificate expiry, disk, memory pressure, backup validation and notification delivery are all monitored.
  • An unusually quiet period is itself treated as a symptom worth investigating.

Backup and recovery

  • Configuration, detection rules, case records and customer configuration are backed up on a schedule, encrypted.
  • Restores are tested. A backup that has never been restored is not a proven backup.
  • Changes to production are preceded by a recorded rollback path that has been verified to work.
  • Destructive operations run behind a dry-run gate that asserts the expected result and aborts on any mismatch.

Certification

What we do not claim

Tech49Originals does not currently hold ISO 27001, SOC 2 or equivalent third-party certification for the Vanguard platform, and we will not imply otherwise. The controls described on this page are engineering and operational decisions we have made and can demonstrate - not an audited attestation.

We would rather state that plainly than display badges that do not mean what a reader would assume. If your procurement process requires certified attestation today, Vanguard may not yet meet that requirement, and we will tell you so during scoping rather than at contract stage.

We are happy to complete security questionnaires, walk your technical team through the architecture, and evidence any control described here.

Responsible disclosure

Reporting a vulnerability

If you have found a security issue in this website or in the Vanguard platform, we want to hear about it.

How to report

Email info@tech49originals.com with “Security disclosure” in the subject line. Please include enough detail to reproduce the issue: the affected URL or component, the steps involved, and what you observed.

What we ask

  • Give us reasonable time to investigate and remediate before any public disclosure.
  • Do not access, modify or delete data belonging to anyone else.
  • Do not run automated scanning that degrades service for other users.
  • Do not use social engineering, physical attacks, or denial-of-service testing.
  • Act in good faith and stay within the scope of demonstrating the issue.

What we commit to

  • We acknowledge reports within two business days.
  • We keep you informed of progress toward a fix.
  • We will not pursue legal action against researchers who follow this policy in good faith.
  • We credit reporters who wish to be credited.

We do not currently operate a paid bug bounty programme. Reports are handled by the engineering team directly.

Get started

Send us your security questionnaire

We are used to procurement and security review processes, and we would rather answer detailed questions early than discover a blocker late.