Security

Designed for restricted environments.

TangleMap is built around local collection and controlled handoff because many Microsoft BI estates cannot expose broad metadata access to an external SaaS tool.

Local collection

The collector runs inside the client environment from an approved host or jump box.

Least privilege

Read-only access is preferred. Partial scans still produce value when permissions are limited.

Encrypted handoff

The MVP/pilot flow uses a password-encrypted evidence bundle for controlled transfer.

No secrets required

Secrets are not needed in the assessment output. Sensitive values are redacted or omitted.

Client-controlled context

Configs, local logs, and local execution context remain client-controlled unless explicitly shared.

Analyst-local tools

The current web/API surfaces are local analyst tooling, not a hosted multi-tenant portal.

Before a pilot

Agree the handling path up front.

  • Run the collector from an approved client host or jump box.
  • Prefer read-only or least-privilege source access, accepting that limited access can reduce coverage.
  • Use password-encrypted bundle output and transfer the password through a separate approved channel.
  • Let the client review the generated log and bundle summary before handoff where practical.

Current boundary

Controlled assessment tooling, not hosted production infrastructure.

The current analyst/API surfaces are local tools. They are not a hosted multi-tenant portal, internet-facing assessment service, or unattended collection agent. Any pilot should keep ingestion and assessment access inside a controlled environment.

Next step

Need to review the security model?

Use a walkthrough to discuss collector placement, access model, bundle handoff, and what does not leave the client environment.