Skip to content

Security

Only scan systems you own or are authorized to assess. Keep access to the Docker host, database, backups, and encryption keys restricted to trusted operators. The repository’s security policy is the canonical reference for security guarantees and vulnerability reporting. Report vulnerabilities privately through GitHub’s security advisory feature; do not put exploit details, target information, or credentials in public issues.

EdgeWatch invokes fixed Nmap and Naabu executables directly with validated argument arrays. Browser settings do not provide arbitrary shell execution, scanner binaries, output paths, or unrestricted NSE scripts. Naabu discoveries must be confirmed by Nmap before they affect baselines or incidents.

Keep target exclusions and probe budgets intact. Review container capabilities before opting into SYN discovery; the default deployment grants only NET_RAW.

Keep the application listener on loopback. Use an SSH tunnel or an HTTPS reverse proxy, approve its hostname, and trust only proxies you control. Sanitize forwarding headers so rate limits and audit records identify the right client. Follow Reverse proxies and the configuration defaults.

Use the least powerful account role appropriate to each person. Enroll administrators in TOTP, keep recovery codes private, and review active sessions and audit records. With multiple business units, TOTP is required for unit administrators and platform administrators. See Accounts and public status and Business units.

Notification URLs are write-only in the API and encrypted in the database with notification.key. TOTP seeds use the independent auth.key. Separate configured key files must have private ownership and mode 0600. Back up the original keys with the corresponding database; the database alone cannot recover them. Never commit keys, passwords, setup tokens, notification URLs, or runtime data.

After a successful legacy notification import, remove plaintext URLs and URL file mounts from the deployment. Rotate credentials through the console. Notifications explains import and delivery behavior.

Restore onto a stopped service. Restores end copied sessions and one-time links, clear copied leases, and quarantine pending notifications by default. Check database compatibility before upgrading or restoring an older backup.

Units share one process, database, and encryption keys. The product isolates unit data in its console, API, streams, and public pages, but host operators can access every unit. Backups and restores cover all units together. Use separate deployments for parties that must not trust the same operators.

The platform administrator manages unit lifecycle and accounts without direct access to unit scan data. Account invitations and password resets are still trusted operations: keep unit administrators on TOTP and review platform account actions in the unit audit. The security policy describes these trust boundaries and the signals that units can observe about one another.

Publish only intended hosts on each unit’s public status page. The public projection excludes raw scan evidence, private fingerprints, and credentials. RDAP uses public registry data only; update checks contact GitHub and disclose the host’s public address and EdgeWatch user agent. Disable either feature in deployment configuration when required.