Security & data handling
Your images stay in your network
OCImend Cloud for organisations runs the decisions; your agent does the work where your images live. What crosses the line is a list of package names and versions, never an image, a file, a secret or a credential.
What the agent sends, and what it never sends
| Sent to OCImend | Never sent |
|---|---|
| Image reference and digest, layer digests and sizes | Image layers, or the content of any file |
| OS release fields (name, version) | Environment variables, configuration files, secrets |
| Installed package names and versions | Registry credentials |
| Application dependency names, versions and paths | Your signing key |
| Go modules compiled into each program | Your source-control token |
| Interpreter paths, whether a shell is present | Labels other than the standard OCI ones |
What comes back: the report (known vulnerabilities, grade, what to fix first), the fix as finished build steps, and the release decision for the rebuilt image, with a record you sign with your own key.
Controls
Single sign-on
OpenID Connect with PKCE, your email domains only, roles from your groups, optional “single sign-on only” for people.
Roles and keys
Viewer, operator, admin; separate agent keys that can do nothing else. Keys are shown once, kept only as hashes, expire, and can be revoked at once.
Audit log
Every sign-in, change, scan, plan, release decision and export, hash-chained, exportable as JSON lines for your SIEM.
Isolation
Per-organisation encryption at rest, every query scoped to the organisation, nothing on public pages or statistics.
Your keys sign
Fixed images are signed by your agent with your key (file, KMS or Vault). Signatures stay out of public transparency logs unless you ask.
Outbound only
The agent connects out over HTTPS. No inbound port, no cluster permissions, a read-only filesystem, non-root.
Release gate
A rebuilt image is released only when it has fewer known vulnerabilities than the original, introduces none that is critical or actively exploited, and (when you ask for the check) starts like the original. Otherwise nothing is pushed, signed or proposed.
Verify what you download
curl -fsSLO https://ocimend.io/downloads/agent/SHA256SUMS curl -fsSLO https://ocimend.io/downloads/agent/SHA256SUMS.sig cosign verify-blob --key https://ocimend.io/cosign.pub --signature SHA256SUMS.sig SHA256SUMS sha256sum --ignore-missing -c SHA256SUMS
Questions
Can OCImend see our images?
Who at our company can see what?
How do people sign in?
Is our data separated from other customers?
How long is data kept?
Can the audit log be altered?
Does the cloud connect into our network?
Report a vulnerability: security.txt · Trust center · Agent documentation