Security & compliance
Security isn't a feature.
It's the architecture.
Last updated: July 2026
FirstSI collects sensitive data about your information system — file access, network flows, DNS queries, software inventory. That responsibility drives every technical choice in the platform, from secret encryption to signed updates.
Our technical guarantees
Strong authentication
Multi-factor authentication (MFA) and WebAuthn — hardware security keys and biometrics. Sessions expire after 15 minutes and renew automatically and transparently.
End-to-end encryption
TLS-encrypted transport between agents, server and your browser. Secrets (API keys, connection credentials) are encrypted at rest in the database.
Complete audit trail
Every sign-in, every administrative action and every data access is logged: who, what, when, from which address. The log can be reviewed and exported at any time.
Signed updates
Agents verify the Authenticode signature of every update before installing it. An unsigned or tampered update is rejected — no exceptions.
Defense in depth
Rate limiting on sensitive endpoints, strict security headers, protection against malicious redirects and forged requests to the internal network (SSRF).
GDPR compliance
FirstSI is built for European organizations and implements the requirements of the General Data Protection Regulation:
- Right of access and portability — one-click export of a user's personal data, in a structured, readable format.
- Right to erasure — purge of personal data on request, including within event logs.
- Data minimization — you choose which modules are active and therefore what data is collected; nothing is collected beyond the configured scope.
- Controlled retention — operational data is archived after 90 days; archive retention is configurable.
- Accountability — the audit trail documents who accessed which data, a key requirement in case of inspection.
For any question about data protection or to exercise your rights: contact@firstsi.com.
Hosting and resilience
- Your data stays with you — FirstSI installs on your own infrastructure (on-premise) or on the hosting of your choice; you keep physical control of the data.
- Outage tolerance — agents buffer data locally if the server is unreachable, then resynchronize automatically. No data loss during network incidents.
- Backups — documented backup and restore procedures, with automatic integrity checks.
Report a vulnerability
Found a security flaw in FirstSI? Write to contact@firstsi.com with the technical details. We commit to acknowledging your report and keeping you informed of the fix. We do not pursue good-faith researchers.