Security and Infrastructure

How Silent Bolt protects the workspaces, credentials and scan data it holds.

Silent Bolt runs real security tools against systems you have proven you own. The controls below are the ones the platform actually enforces today — not a roadmap.

Tenant Isolation

Every record — targets, scans, findings, reports — is scoped to the workspace that owns it, and handlers verify that ownership on each request. One customer cannot see or scan another customer’s assets.

Authorization Before Scanning

A domain has to be verified with a DNS TXT record or an email challenge, and then authorized by an admin, before any scan can start against it.

Encrypted Credentials

AI provider keys and tool credentials are encrypted at rest and stored per workspace, so one company’s identity tenant can never be reached from another company’s session.

Container-Isolated Execution

Scan and orchestration tools run in isolated containers with their own resource limits, kept away from the application process.

Human Approval for Intrusive Tools

Passive and active tools run automatically; intrusive ones stop the session and wait for a person who can approve them. AI-generated arguments are sanitized and conflict-checked first.

Role-Based Access

Members hold one of three roles — manager, editor or viewer — alongside a single workspace owner, and the least-privileged role is the default for anyone newly invited.

Audit Logging

Security-relevant operations, including finding governance transitions and deletions, are written to an audit trail with the actor, the timestamp and the reason given.

Encrypted Transport and Sign-In

All traffic runs over TLS. You can sign in with Google or Microsoft, which brings your identity provider’s own controls, including MFA, to your account.

Questions from your security team?

Send them over — we would rather answer a hard question before you onboard a domain than after.

Contact us