OCImendby CloudTrace

Security & data handling

Your images stay in your network

OCImend Cloud for organisations runs the decisions; your agent does the work where your images live. What crosses the line is a list of package names and versions, never an image, a file, a secret or a credential.

What the agent sends, and what it never sends

Sent to OCImendNever sent
Image reference and digest, layer digests and sizesImage layers, or the content of any file
OS release fields (name, version)Environment variables, configuration files, secrets
Installed package names and versionsRegistry credentials
Application dependency names, versions and pathsYour signing key
Go modules compiled into each programYour source-control token
Interpreter paths, whether a shell is presentLabels other than the standard OCI ones

What comes back: the report (known vulnerabilities, grade, what to fix first), the fix as finished build steps, and the release decision for the rebuilt image, with a record you sign with your own key.

Controls

Single sign-on

OpenID Connect with PKCE, your email domains only, roles from your groups, optional “single sign-on only” for people.

Roles and keys

Viewer, operator, admin; separate agent keys that can do nothing else. Keys are shown once, kept only as hashes, expire, and can be revoked at once.

Audit log

Every sign-in, change, scan, plan, release decision and export, hash-chained, exportable as JSON lines for your SIEM.

Isolation

Per-organisation encryption at rest, every query scoped to the organisation, nothing on public pages or statistics.

Your keys sign

Fixed images are signed by your agent with your key (file, KMS or Vault). Signatures stay out of public transparency logs unless you ask.

Outbound only

The agent connects out over HTTPS. No inbound port, no cluster permissions, a read-only filesystem, non-root.

Release gate

A rebuilt image is released only when it has fewer known vulnerabilities than the original, introduces none that is critical or actively exploited, and (when you ask for the check) starts like the original. Otherwise nothing is pushed, signed or proposed.

Verify what you download

curl -fsSLO https://ocimend.io/downloads/agent/SHA256SUMS
curl -fsSLO https://ocimend.io/downloads/agent/SHA256SUMS.sig
cosign verify-blob --key https://ocimend.io/cosign.pub --signature SHA256SUMS.sig SHA256SUMS
sha256sum --ignore-missing -c SHA256SUMS

Questions

Can OCImend see our images?
No. With the agent, images are read inside your network and only package names and versions are sent. The fixed image is built, pushed and signed with your tools, your registry and your key.
Who at our company can see what?
Roles: viewers see reports, operators start scans and fixes, admins manage members, keys, single sign-on and settings. Agent keys can only send inventories and take jobs. Every action is in the audit log.
How do people sign in?
With your identity provider over OpenID Connect (Okta, Microsoft Entra ID, Google Workspace, Auth0, Keycloak and others), restricted to your email domains, with roles mapped from your groups. You can require it for everyone.
Is our data separated from other customers?
Yes. Each organisation's reports are encrypted at rest with a key derived for that organisation alone, every query is scoped to it, and nothing from an organisation ever appears on public pages, statistics or the registry.
How long is data kept?
Reports: 90 days by default, from 7 to 730 days, your choice. The audit log is kept for the life of the organisation and can be exported at any time.
Can the audit log be altered?
Each entry carries the hash of the one before it, so an edit or a deletion breaks the chain; the console and the API verify the chain on demand.
Does the cloud connect into our network?
Never. The agent connects out over HTTPS to ask for work and report results; it needs no inbound port and no cluster permissions.

Report a vulnerability: security.txt · Trust center · Agent documentation

Try it with your own registry.

Request a trial → Sign in