Security

You are considering software that can change your DNS. Here is exactly what it may and may not do.

Monitoring is a read-only decision. Remediation is not. This page answers the questions an operator should ask before letting anything touch production — plainly, and without claiming certifications we do not hold.

The short answers

Each label says whether something is on by default today, off unless you enable it, or still on the roadmap. Nothing here is aspirational unless it says so.

On by default

Can SystemsWarden act without my approval?

No. Every account starts read-only. Remediation is a separate capability, it belongs to the Autopilot plan, and enabling it is an explicit act by an account administrator.

When you do enable it, it starts in shadow mode: it publishes the action it would have taken and performs nothing. Arming execution is a second, separate decision.

You define it

Can I restrict what it is allowed to do?

That is the design. You define which nodes are eligible targets, minimum free capacity, per-node cooldowns, how far load may be spread, and any jurisdiction rule that forbids a class of target outright.

A target excluded by your policy is dropped before scoring begins. It cannot be chosen because it looked healthy.

On by default

Is everything audited?

Yes, and it is enforced in one place rather than left to each feature. Every state-changing operation goes through a single audit call that writes the action log and sends the notification.

A change that is not logged cannot be applied, because the log entry is written first. You get a global history and a per-domain history.

On by default

How are credentials stored?

DNS and provider credentials are held server-side, encrypted at rest, and are never sent to the browser or to an agent. The dashboard shows the last four characters and nothing more.

Scope them down at the provider: SystemsWarden only needs permission over the zones and records you intend it to manage.

On by default

Can I revoke an agent?

Yes, from the dashboard, immediately. A revoked agent's ingest token stops being accepted on the next request; nothing needs to be uninstalled first.

Agents authenticate with a per-node ingest token, speak outbound-only over TLS, and never accept inbound connections. There is no port to expose.

On by default

What happens if SystemsWarden goes down?

Nothing moves. Remediation is fail-closed: with no confirmed multi-region verdict there is no action, and your DNS and proxy configuration keep serving exactly as they are.

Detection runs from edge locations independent of the control plane, so a control-plane outage cannot manufacture a false failure either.

The rules that constrain an automatic action

These are not advisory. Each one is a gate that a proposed action must pass; failing any single gate stops the action and, where relevant, escalates instead.

Nothing is deleted. A drained node stays in your fleet marked as draining, and a removed endpoint is recorded rather than discarded. Every automatic action is designed to be reversible by a single operator decision.

Data, transport and the agent

What actually leaves your servers, over what channel, and how long it is kept.

What we do not claim. SystemsWarden does not currently hold SOC 2, ISO 27001 or an independent penetration-test report. If your procurement requires one, say so when you contact us and we will tell you honestly where that stands rather than pointing at a badge.

Still have a question this page did not answer?

Send it. Security questions get a direct answer from someone who works on the system, not a form letter.