Security is foundational to a platform built for security operations. This page summarises our approach at a high level. Customers under agreement can request further detail through their account contact.
Data protection
Data is encrypted in transit using industry-standard TLS, and we apply encryption for data at rest on supported storage. We follow the principle of collecting and retaining only what is needed.
Tenant isolation
VultSight is multi-tenant by design. Customer data is logically isolated, with row-level controls and per-tenant separation across search and storage, so one tenant's data is not accessible to another.
Access control
Access to systems and data follows least-privilege principles. The platform supports enterprise single sign-on (SAML and OIDC), granular role-based access control, and time-limited emergency ("break-glass") access with full audit.
Auditing and integrity
Significant actions are recorded in a tamper-evident audit trail, helping customers demonstrate accountability and detect unauthorised changes.
Zero-day & emerging threats
New exploits rarely arrive with a signature. VultSight detects them by behaviour — UEBA baselines and MITRE ATT&CK technique detection flag the actions an exploit takes (credential access, lateral movement, C2), not just known indicators — and operationalises threat intelligence such as CISA KEV, Sigma and OSINT feeds in real time. When a new indicator is published, historical events can be swept retroactively, containment can be automated through response playbooks, and vulnerability-scan data (e.g. Tenable, Qualys) is ingested to prioritise exposed and business-critical assets. How VultSight handles zero-days →
Infrastructure
The platform runs on reputable cloud infrastructure with availability and redundancy appropriate to the deployment model. On-premises and hybrid options are available for organisations with data-sovereignty requirements.
Compliance posture
We design our controls to align with widely recognised security and privacy best practices, and we provide capabilities — such as data-residency controls and configurable retention — to help customers meet their own regulatory obligations, including GDPR and CERT-In considerations. Detection is mapped to MITRE ATT&CK and supports Sigma and STIX/TAXII; the compliance module lets you map controls to the frameworks you report against — for example NIST CSF, ISO 27001, PCI-DSS, CERT-In or GDPR. Specific compliance documentation can be discussed under agreement.
Responsible disclosure
We welcome reports from the security community. If you believe you have found a vulnerability, please email security@vultsight.com with enough detail to reproduce the issue. We ask that you give us a reasonable opportunity to investigate and remediate before any public disclosure, and that testing avoids privacy violations, data destruction or service disruption. We will acknowledge legitimate reports and work with you in good faith.
Contact
For security questions, contact security@vultsight.com.