Trust and transparency

Know what Infraveil can see and do.

Trust starts with a clear boundary. Your application runs on servers you control. Infraveil hosts the management dashboard and receives the operational information needed to manage and explain those services.

On your servers

Your running application

Your application code, process environment, and persistent files remain on infrastructure you control. A local runtime component carries out the managed work for that server.

Hosted by Infraveil

The management dashboard

The dashboard receives operational data needed to show connected servers, managed services, releases, health, changes, and incidents. Do not interpret “your servers” as “no data leaves your servers.”

Authority

You choose how managed changes are approved.

Different work needs different friction. Infraveil supports three approval modes rather than pretending every change always waits for a person.

Manual

A person reviews and approves the managed action before it runs. Use this for high-risk work.

Allowlist

Known-safe actions can proceed when they match the rule you defined. Anything else stops.

Automatic

Approved categories can run without a manual step where your operating policy allows it.

Evidence

Check managed changes in context

The product records operational facts about managed releases and actions so a team can connect an incident to what changed. The value is the inspectable record—not a trust badge.

Source visibility

Be precise about what is inspectable

Runtime components installed on your servers are source-visible there. This website provides browser tools and product documentation. The hosted management dashboard is private.

Current limitation: Infraveil has not completed an independent external security audit. Product evidence, public material, and source-visible installed components are useful inputs, but they are not a third-party certification.

Need the technical version?

The architecture paper explains components, trust boundaries, data flow, approval modes, failure behavior, and current limits without exposing private backend source or secrets.