GreyAware Request a demo
Menu

Security & data handling

Understand the controls behind your evaluation.

Review how GreyAware handles platform access, connected data, and managed credentials. Establish the deployment requirements and operating responsibilities that matter to your organization.

Platform access

Match access to the work people do.

GreyAware provides application controls for sign-in, roles, and organizational scope. Review the configured permissions with the people who will administer and use your environment.

SAML single sign-on

Connect a supported SAML identity provider and configure the trust settings and claim mappings for your tenant. Validate sign-in and access assignments as part of setup.

Roles and scoped access

Role permissions distinguish administrative, operational, and read-only access. Membership scope supports tenant, child-tenant, and business-unit boundaries where applicable to the workflow.

Audit records

Recorded administrative and operational events include actor, time, action, and target context. Authorized users can review available audit and activity records during an investigation.

Connected data

Review what connects, what is stored, and who can use it.

Depending on the integrations you configure, GreyAware processes asset, software, identity, access, and security-control records to support investigation and planning.

01 · Source systems

Configured integrations

Source permissions and supported datasets determine which records are available.

02 · GreyAware

Connected evidence

Records are normalized and correlated into inventory, relationships, findings, and history.

03 · Your team

Scoped investigation

Users review the available evidence through their assigned roles and access scope.

  1. Integration permissions

    Review required permissions for each connector and use case. Supported connectors offer dataset selection and access checks; requirements vary by source and enabled workflow.

  2. Managed credentials

    The built-in managed-secret store encrypts credentials it manages, including integration and console-configured SMTP secrets. Customer-hosted setup includes a dedicated encryption key and protected runtime secret files.

  3. Data scope

    Agree on the sources and datasets needed for the evaluation. Review identity records, operational metadata, and any external service connections against your organization’s requirements.

Deployment & lifecycle

Make the operating responsibilities explicit.

GreyAware supports a customer-hosted deployment path. Plan hosting, network access, data retention, and recovery alongside application setup.

Explore the Design Partner Program

Hosting and transport

Customer-hosted production setup uses a configured HTTPS edge proxy. Host and disk encryption, infrastructure access, and network rules are part of the deployment plan.

Retention controls

Configurable cleanup settings cover supported history and stale-inventory categories. Review the retained data types and time windows for your use case, alongside backup retention and any contractual requirements.

Backup and recovery

The customer-hosted runbooks cover database backup and restore, optional off-host storage, and separate protection of runtime secrets and encryption keys. Agree on operational ownership and validate a restore as part of deployment readiness.

Prepare your review

Bring the requirements your team needs to verify.

We can discuss the relevant configuration, integration scope, and operating model before an evaluation begins.

This page summarizes product controls and deployment considerations. Your configuration and applicable agreement define the details for your environment.

What should we bring to a security discussion?

Bring your identity provider, proposed source systems, required datasets, hosting constraints, and retention expectations. Include any security questionnaire or procurement requirements you need to address.

Does every integration use the same permissions?

No. Permissions depend on the provider, datasets, and workflow. We review the intended connection and access requirements for the sources involved in your evaluation.

How should we evaluate encryption?

Review managed-secret protection, HTTPS configuration, host and database storage, and backups as separate parts of the deployment. Encryption of managed credentials describes that store; protection of the wider environment depends on the configured infrastructure.

Where will our deployment and data reside?

For a customer-hosted deployment, your organization selects the hosting environment. Review connected source systems and any configured external services as part of the data-flow discussion. Bring regional or residency requirements into the initial scoping conversation.

What information is collected by this website?

Contact requests are processed by our contact service and Tines workflow. Optional Google Analytics runs after a visitor accepts analytics. You can change that choice through Analytics preferences in the footer. See our Privacy policy for the website and customer-data notice.

Plan your evaluation

Discuss your security requirements with us.

Connect the product workflow with the access, data, and deployment requirements your organization needs to evaluate.