For the procurement, GRC, or vendor-risk reviewer running a SIG-Lite / CAIQ / VSAQ-style evaluation. Companion to /trust — that page answers "what does the agent on my machine see?"; this page answers "is this vendor safe to do business with?". The honest version of both, without legalistic hedging.
DataStun is a three-tier system. The endpoint agent runs on customer machines (Linux / Windows / macOS) as a kardianos/service-managed background process. The tenant platform (ten) handles agent enrollment, telemetry ingest, customer dashboards, and billing. The reputation system (rep) handles destination-IP investigation and threat-feed ingestion.
tenant.datastun.com over TCP/443. No peer-to-peer fanout, no STUN-style NAT punching from the agent toward the platform.tenant_id on every customer-data row). Per-tenant database isolation lands on paid tiers as part of the federation rollout.dta_, HMAC-hashed at rest. Scope is limited to the single agent the key was issued to.dtet_ prefix) tied to the install-package’s tenant + tier-bound seat count.last_used_at (once per minute) limits replay-style abuse./staff/*) gate on an explicit email allowlist (STAFF_EMAIL_ALLOWLIST). A real RBAC role layer is on the iteration-2 roadmap.Tenant deletion is a single click in the in-product privacy controls. Deletion cascades through all per-tenant tables in a single transaction. Backups age out on a 30-day rolling window; deleted tenants drop out of backup at the latest backup-age boundary.
The actual production list. We commit to updating this page when it changes.
| Subprocessor | Purpose | Customer data exposure |
|---|---|---|
| Cloudflare | DNS, TLS termination, Cloudflare Tunnel for ingress. | Sees TLS-terminated request headers and bodies in flight; does not store payloads. |
| SendGrid (Twilio) | Transactional email (signup verification, password reset, alert digests). | Sees recipient email addresses and email body content. |
| Anthropic | Stage-10 AI advisory assessment in the reputation pipeline (Claude Haiku). Strictly advisory; never mutates grade or score. | Sees IP address + service-identification context for the IP under investigation. No customer fleet data sent. |
| MaxMind | GeoLite2 City + ASN database for IP geolocation. Local file lookup; no live API calls. | No data sent to MaxMind during operation. Database refreshed periodically. |
| VirusTotal | Multi-engine file-hash reputation lookup (the “VT” chip in the executable verdict cluster). | SHA-256 file hashes only. No binaries uploaded. No customer attribution sent. |
| MalwareBazaar (abuse.ch) | Public malware-sample corpus lookup (the “MBZ” chip). | SHA-256 file hashes only. No customer attribution sent. |
| NSRL (NIST) | Federal known-good file catalogue. Local SQLite database; no live API. | No data sent during operation. Database mirrored on rep. |
| ip-api.com Pro | Geo / ASN / mobile / proxy / hosting-flag enrichment for stage-1 of the IP investigation pipeline. | Destination IP under investigation. No customer attribution sent. |
| LinkedIn OAuth | Optional sign-in path for the customer dashboard. | Email + LinkedIn profile fields the user explicitly grants on the OAuth consent screen. |
Hosting / infrastructure: today on Bill’s in-region infrastructure. The Vultr migration adds a hosted-cloud subprocessor; this list is updated when that lands.
If you find a security issue in any DataStun component, please report it to [email protected].
A formal CVD policy and bug-bounty program will land alongside the SOC 2 work. Today the address and the commitments above are operative.
A working production platform, real customers, written and self-binding Privacy Policy and Terms of Service, in-product transparency surfaces (/data-collection, in-tenant privacy controls), defensible architecture decisions documented in the /trust page.
SOC 2 Type II report (work scoped, audit firm not yet engaged). Penetration test by an external firm (internal review only so far). Formal bug-bounty program. CISA / DHS conformance attestation. ISO 27001 certification. SAML / OIDC SSO ships on Enterprise but is in active rollout, not GA across the whole platform.
The Privacy Policy and Terms of Service are operative on us today as written; counsel review will tighten the language but cannot expand what we collect or weaken commitments we’ve already made publicly. If a clause changes materially before commercial launch, the change is announced and existing customers are grandfathered into the more-favorable version. Privacy Policy · Terms of Service.
Pretending we have SOC 2 today would waste your time and ours. The honest answer is that the controls are in place, the documentation is being built, and the audit is on the roadmap. If your organization requires SOC 2 to use a vendor, please tell us — that signal accelerates the audit timeline.
Where DataStun sits today against common frameworks. Use this as a starting point; specific control mappings are available on request.
For security-review questions, vulnerability reports, or DPA / BAA / questionnaire requests:
For questions this page didn’t answer, the contact form at /contact routes directly to the security inbox.
If your reviewer wants to see the product in action while the questionnaire is in flight: sign up free, enroll one agent on a sandbox machine, and the dashboard surfaces (Trust, Data Collection, Privacy Settings) are fully populated for inspection.