Local collection
The collector runs inside the client environment from an approved host or jump box.
Security
TangleMap is built around local collection and controlled handoff because many Microsoft BI estates cannot expose broad metadata access to an external SaaS tool.
The collector runs inside the client environment from an approved host or jump box.
Read-only access is preferred. Partial scans still produce value when permissions are limited.
The MVP/pilot flow uses a password-encrypted evidence bundle for controlled transfer.
Secrets are not needed in the assessment output. Sensitive values are redacted or omitted.
Configs, local logs, and local execution context remain client-controlled unless explicitly shared.
The current web/API surfaces are local analyst tooling, not a hosted multi-tenant portal.
Before a pilot
Current boundary
The current analyst/API surfaces are local tools. They are not a hosted multi-tenant portal, internet-facing assessment service, or unattended collection agent. Any pilot should keep ingestion and assessment access inside a controlled environment.
Next step
Use a walkthrough to discuss collector placement, access model, bundle handoff, and what does not leave the client environment.