Tenant Isolation
Every record — targets, scans, findings, reports — is scoped to the workspace that owns it, and handlers verify that ownership on each request. One customer cannot see or scan another customer’s assets.
How Silent Bolt protects the workspaces, credentials and scan data it holds.
Silent Bolt runs real security tools against systems you have proven you own. The controls below are the ones the platform actually enforces today — not a roadmap.
Every record — targets, scans, findings, reports — is scoped to the workspace that owns it, and handlers verify that ownership on each request. One customer cannot see or scan another customer’s assets.
A domain has to be verified with a DNS TXT record or an email challenge, and then authorized by an admin, before any scan can start against it.
AI provider keys and tool credentials are encrypted at rest and stored per workspace, so one company’s identity tenant can never be reached from another company’s session.
Scan and orchestration tools run in isolated containers with their own resource limits, kept away from the application process.
Passive and active tools run automatically; intrusive ones stop the session and wait for a person who can approve them. AI-generated arguments are sanitized and conflict-checked first.
Members hold one of three roles — manager, editor or viewer — alongside a single workspace owner, and the least-privileged role is the default for anyone newly invited.
Security-relevant operations, including finding governance transitions and deletions, are written to an audit trail with the actor, the timestamp and the reason given.
All traffic runs over TLS. You can sign in with Google or Microsoft, which brings your identity provider’s own controls, including MFA, to your account.
Send them over — we would rather answer a hard question before you onboard a domain than after.
Contact us