Localhost-first
The pilot binds to 127.0.0.1 by default and is not intended for public reverse-proxy exposure.
SECURITY
EVIDRYN's founder-assisted pilot is designed for controlled local use, with no SIEM writeback, no autonomous response and no automatic external provider calls.
TESTED PILOT BOUNDARIES
EVIDRYN Pilot 0.2.0 uses a local workspace, bounded file handling and protected local mutations. These controls reduce exposure; they do not make any system invulnerable.
The pilot binds to 127.0.0.1 by default and is not intended for public reverse-proxy exposure.
Unsafe Host values, untrusted mutation origins and invalid mutation protection are rejected.
Runtime cases, evidence, reports and backups stay in explicit local paths selected for the pilot.
EVIDRYN imports authorized exports and does not write back, acknowledge or delete Wazuh alerts.
EVIDRYN Guide never executes its starter queries and requires environment-specific analyst adaptation.
Backups use file manifests and SHA-256 verification but do not currently provide archive encryption.
DEPLOYMENT REQUIREMENTS
Backup archives are integrity-verified but unencrypted. Store them on access-controlled encrypted media where organizational policy requires it.
Responsible disclosure process