legal

Security & Technical Measures

Last updated: 2026-09-11. Governing law: Israel.

Security and Technical & Organizational Measures

This page describes the technical and organizational measures EyalSec applies to the EyalSec / es2 Service. It is the public statement of our security posture, and it is incorporated into the Data Processing Agreement (/legal/dpa) as Annex II, satisfying GDPR Article 32 and Clause 8.6 of the Standard Contractual Clauses.

Published by Eyal Gabay, trading as "EyalSec", sole proprietor (osek murshe) no. 211868450, Israel. Security contact: security@eyalsec.com.

Honest framing. EyalSec is a small, independent business. The measures below are real and are described accurately, including where they are limited. We hold no third-party security certification (no ISO 27001, no SOC 2), and we do not claim one. If your procurement process requires a certification, tell us before you buy rather than after.


1. Data residency and hosting

2. Encryption

| Where | Measure | |-------|---------| | In transit | TLS for every connection to the dashboard, the public site, the API and the agent ingestion endpoint. Certificates are issued and renewed automatically. Plain HTTP is redirected. | | At rest | The storage volume holding the database, artifacts and application state is encrypted. | | Backups | Automated database backups are encrypted before they leave the host, and are only ever stored encrypted. | | Credentials | Account passwords are stored with bcrypt. API keys are stored only as hashes. Two-factor secrets are encrypted at rest under a key held independently of the session key. |

3. Access control and authentication

4. Network and platform controls

5. Host and production hardening

6. Secure development and release

7. Logging, monitoring and resilience

8. Data handling, retention and deletion

9. Personnel

10. Personal data breach response

If we become aware of a personal data breach affecting a customer's data, we notify that customer without undue delay, with the information available to us: the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed. We provide further information as it becomes available and assist the customer with its own notification obligations. See Section 6(f) of the DPA.

Where we are the controller, we notify affected individuals and the competent supervisory authority as the law requires.

11. Vulnerability management and disclosure

We operate a coordinated vulnerability disclosure policy at /legal/vulnerability-disclosure, with a safe harbour for good-faith research. Report suspected vulnerabilities to security@eyalsec.com.

Dependencies are scanned for known vulnerabilities as a release gate (Section 6). Where a published release of an agent has known issues, we may publish them; customers are responsible for running the current published version (Terms, Section 9).

12. Security of the agents on your systems

The agents run inside your environment, and its security is yours (Terms, Section 6(d)). This applies to every agent: es-python, es-chromium, es-c, es-cpp, es-rust, es-node, es-solidity, es-bash and es-php. What we do on our side:

What stays on your machine. Your source code, your project files, and the data your programs process are not uploaded. What travels to your dashboard is the detection event: the operation that fired, where it happened, where the data came from, and the value that triggered it. That value can itself be sensitive, which is why Section 6(b) of the Terms and Section 2 of the Privacy Policy say so explicitly and why the configuration controls exist.

13. Regulatory posture

14. Questions, questionnaires and audits

Send security questionnaires and due-diligence requests to security@eyalsec.com. Audit rights, and their limits, are at Section 6(i) of the DPA.

15. Changes

We may update this page as the Service evolves. Material reductions in the measures described here will be notified to affected customers in advance, as the DPA requires.

EyalSec Pricing Docs Security Login Book a live demo