Security architecture

Keep customer-network
access local.

Equate’s architecture separates the customer OOB monitoring plane from the UI/UX cloud plane. The collector sends telemetry outward; the cloud does not manage devices or credentials inside the customer network.

Outbound-only transport
Collectors initiate TLS-authenticated MQTT connections with QoS 1. No cloud-initiated management path is part of the product architecture.
Secret boundaries
SNMP communities, TLS material, environment values, and local operator controls are not sent to cloud clients or dashboard views.
Local administration
Inventory, discovery, and policy changes are local collector operations protected by Unix-socket and operating-system access controls.
Read-only presentation
The dashboard reads monitoring state through the API. It does not access collectors, MQTT, or PostgreSQL directly.

Technical security information

See the curated security model for documented boundaries and operational controls. Product policies and compliance commitments require separate approval.