SECURITY

Local-first. Explicitly bounded. Analyst-controlled.

EVIDRYN's founder-assisted pilot is designed for controlled local use, with no SIEM writeback, no autonomous response and no automatic external provider calls.

TESTED PILOT BOUNDARIES

Security is defined by explicit limits.

EVIDRYN Pilot 0.2.0 uses a local workspace, bounded file handling and protected local mutations. These controls reduce exposure; they do not make any system invulnerable.

Network

Localhost-first

The pilot binds to 127.0.0.1 by default and is not intended for public reverse-proxy exposure.

Requests

Local web controls

Unsafe Host values, untrusted mutation origins and invalid mutation protection are rejected.

Storage

Customer-controlled workspace

Runtime cases, evidence, reports and backups stay in explicit local paths selected for the pilot.

SIEM

Read-only source boundary

EVIDRYN imports authorized exports and does not write back, acknowledge or delete Wazuh alerts.

Guide

Display-only queries

EVIDRYN Guide never executes its starter queries and requires environment-specific analyst adaptation.

Backups

Verified, not encrypted

Backups use file manifests and SHA-256 verification but do not currently provide archive encryption.

DEPLOYMENT REQUIREMENTS

Run the pilot on a trusted workstation.

  • Use a patched, trusted Windows or Linux workstation
  • Keep the server bound to localhost
  • Do not configure public port forwarding or a public reverse proxy
  • Restrict workspace and backup access
  • Use full-disk encryption where available
  • Obtain written authorization before importing organizational alerts

Treat backups as sensitive

Backup archives are integrity-verified but unencrypted. Store them on access-controlled encrypted media where organizational policy requires it.

Responsible disclosure process