Trust and transparency

Know what Infraveil can see and do.

Infraveil coordinates operations through a hosted control plane while local launcher and agent components perform configured work on your servers. The boundary below explains runtime authority, release approval, and the information shared with the hosted service.

On your servers

Your running application

Your running application, process environment, and persistent files remain on infrastructure you control. Local components start and supervise configured services and operate supported gateway routes.

Hosted by Infraveil

The management dashboard

The hosted control plane coordinates releases and settings and receives selected operational data, including service health, logs, changes, and incidents. Managed-package uploads may include application source; running on your servers does not mean all information stays local.

Authority

Choose how releases are approved.

These are release-signing policies, not blanket permission for every operational action. Assistant and remediation features use separate permissions and review settings; choosing automatic release approval does not grant every assistant capability.

Manual

Review a pending release before your customer-held key signs its exact hash. This preserves a per-release review step on the deployment path using that gate.

Exact-hash allowlist

Preapprove specific release hashes. Matching pending hashes can be signed without another prompt; only hashes you added are preapproved.

Automatic

Sign every pending release hash while this mode is enabled. It removes the per-release human review step; use it only when that is the policy you intend.

Evidence

Check managed changes in context

Review release changes and managed actions alongside the affected service’s health, logs, and incidents. The history helps explain what was requested and reported; it does not substitute for checking the service or independently reviewing security.

Source visibility

Be precise about what is inspectable

Runtime components installed on your servers are source-visible there. This website provides browser tools and product documentation. The hosted management dashboard is private.

Current limitation: Infraveil has not completed an independent external security audit. Product evidence, public material, and source-visible installed components are useful inputs, but they are not a third-party certification.

Need the technical version?

The architecture paper explains components, trust boundaries, data flow, approval modes, failure behavior, and current limits without exposing private backend source or secrets.