Security & trust

Automation with boundaries your IT team controls

ASTRA gathers evidence before acting, limits execution to known remediations, and keeps sensitive decisions with authorized people. These controls are implemented in the platform and Windows agent, not left to prompt instructions.

Core controls

Defense in depth from API to endpoint

A remediation must pass policy checks in the cloud and execution checks on the device.

Code-enforced approval tiers

Every remediation is classified as automatic, approval-required or admin-only. The backend enforces who may approve an action; the AI cannot promote its own permissions.

Independent action allowlists

The backend validates requested remediations and the Windows agent maintains its own hardcoded allowlist. Unknown action identifiers are refused at the endpoint.

Role-based access

Organization-scoped API access and role checks separate end users, technicians, administrators and platform operators. Sensitive mutations require the appropriate role.

Auditable operations

Mutations and commands sent to devices are recorded with organization, actor and action context so authorized teams can review what happened.

Outbound-only agent connectivity

The Windows agent initiates outbound HTTPS connections on port 443. Customers do not need to expose inbound device ports for ASTRA.

Protected credentials

Device credentials are stored with Windows DPAPI using LocalMachine scope. Supported integration credentials are encrypted before database storage.

Data handling

Clear operational safeguards

ASTRA is designed to minimize exposed interfaces and keep customer data separated by organization. Exact retention and deployment requirements can be reviewed during a pilot.

  • Short-lived access tokens with single-use rotating refresh tokens
  • HTTPS for portal, API and agent communication
  • Organization-scoped access to telemetry and audit records
  • Raw telemetry retention configurable by deployment; production defaults are documented and reviewed
  • No arbitrary PowerShell or unrestricted command execution path
  • Post-remediation status reporting so teams can confirm the outcome

Need a security review before a pilot?

We can walk your technical team through the action catalogue, approval flow, network requirements and audit trail.