The Only "Zero-Retention" Diagnostic Platform
Traditional RMMs store your data in their cloud, creating a massive target. Secronyx leaves your data where it belongs: On the Endpoint.
Two Models. One Clear Winner.
See how your data is handled under each approach
Others (The "Honeypot" Model)
-
Continuous telemetry upload
Bulk data streamed to vendor cloud 24/7
-
PII stored in vendor's cloud database
Creating a high-value target for attackers
-
"God Mode" write access
Risk of supply chain attack via vendor compromise
Secronyx (The "Flashlight" Model)
-
Data queried on-demand, never stored
Only retrieved when you ask a question
-
No PII retention in our cloud
Nothing to steal, nothing to leak
-
Read-Only permissions by default
Cannot modify, execute, or change anything
Security by Design
Technical proof for our zero-liability claim. Every layer is hardened.
Least Privilege
The agent runs with minimal permissions. Read-only, no shell access, no file modification, no elevated privileges.
TLS 1.3 Encryption
End-to-end encryption for all queries and responses. No plaintext data ever leaves the endpoint.
Ephemeral Execution
Memory-only processing with no disk caching. Diagnostic results are never written to the local filesystem.
Signed Binaries
Tamper-proof executables with cryptographic signatures. Verify integrity before every deployment.
Built for Regulated MSPs
Features designed from the ground up for compliance-first environments
Immutable Audit Logs
Every natural language query ("Show me passwords") is logged. You know exactly who asked what, and when.
Ephemeral Processing
Data is processed in RAM and discarded immediately after the answer is delivered. We cannot lose what we do not have.
Role-Based Access Control (RBAC)
Restrict diagnostics to specific clients or device groups. Junior techs see only what they need.
Core Security Principles
The platform is built on these non-negotiable principles
Explicit, Auditable Data Access
- The AI cannot access machines implicitly
- Every data access requires a specific diagnostic query
- Every query and response is fully logged
Read-Only Execution
- The endpoint agent cannot modify system state
- No write operations, command execution, or configuration changes
- Diagnostic queries are finite, versioned, and deterministic
AI Outside the Trust Boundary
- No general-purpose AI runtime executes on customer machines
- AI reasoning occurs centrally
- Endpoints expose only a constrained diagnostic interface
Data Minimisation by Design
- Only the minimum data required to answer a question is returned
- No bulk telemetry, background scraping, or speculative collection
- Data remains on the endpoint unless explicitly requested
Full Accountability & Traceability
- Every diagnostic session produces a complete audit trail
- All AI actions are attributable, reviewable, and replayable
- Audit logs are immutable and available for export
The Key Distinction
Traditional tools collect everything because they don't know what will matter. Secronyx asks the right questions and collects only what matters.
Standards & Regulatory Alignment
Designed to support compliance with major security and privacy frameworks
ISO/IEC 27001:2022
The platform exceeds ISO expectations by auditing AI intent, not just user actions.
NIST SP 800-53 (Rev. 5)
NIST AI Risk Management Framework
UK Public Sector Alignment
NCSC Principles
- Least privilege: No write access, no blanket visibility
- Defence in depth: AI kept outside endpoint trust boundary
- Audit and monitoring: Full, reviewable diagnostic trail
UK GDPR
- Article 5(1)(c) - Data minimisation: Only queried data is processed
- Article 30 - Records of processing: Diagnostic audit logs support Article 30 documentation2
UK Government Service Standard – Aligned Themes3
- Clear accountability
- Evidence-based assurance
- No opaque automation
- Deterministic, reviewable behaviour
1 Secronyx additionally captures AI reasoning context beyond standard AU-3 requirements.
2 Audit logs provide supporting evidence; a complete Article 30 record requires additional organisational documentation per ICO guidance.
3 These themes align with the intent of the Service Standard; bullet points are not official standard wording.
Complete Auditability & Traceability
Every interaction between the AI and a customer machine is explicit, logged, and reviewable.
For every diagnostic session, the platform records:
-
What the AI asked for
The exact query, timestamp, machine, and tenant context
-
What the AI received
Structured output only, with verifiable link to originating machine
-
Why follow-up questions were asked
The reasoning chain and query dependencies
-
Who or what initiated the session
User, workflow, or policy trigger with full auth context
Audit Log Properties
The AI does not "see everything." It asks explicit questions, receives explicit answers, and leaves an explicit trail.
Risk Mitigation
How Secronyx addresses common security and compliance concerns
Safer Than Local AI Assistants
Many organisations use AI coding assistants running on developer laptops, home machines, or inside production servers. These tools often operate with broad filesystem access, implicit context, and limited auditability.
Risks of Local/In-Production AI Assistants
-
Unprovable data exposure
Difficult to demonstrate what was accessed or shared
-
Write and execution privileges
Blurs responsibility for changes
-
Loss and integrity risk
Local machines may be lost, stolen, or unbackup
-
Expanded attack surface
Each embedded runtime introduces new dependencies
How Secronyx Avoids These Risks
-
No general-purpose AI runs on customer machines
-
The agent is strictly read-only
-
Queries are finite, versioned, and auditable
-
AI reasoning happens outside the trust boundary
-
Every request and response is logged
DPIA-Ready by Design
The platform processes less data than traditional monitoring tools, with stronger controls and traceability
Purpose of Processing
To diagnose system configuration, health, and operational state on demand, in response to explicit user or policy-initiated requests.
Data Subjects
Employees or system users indirectly associated with managed devices. No personal profiling or behavioural analysis is performed.
Data Minimisation
- Data collected is strictly limited to the diagnostic question
- No background collection occurs
- Retention periods are configurable by tenant
Excluded by Design
No continuous logs, keystrokes, screen capture, bulk process memory dumps, personal content, or user activity streams.
Security Questionnaire Reference
Common questions from security and compliance teams
Does your agent have write or execution access on customer systems?
No. The agent is strictly read-only. It cannot modify files, configurations, registry entries, or system state, and it cannot execute arbitrary commands.
Does the platform continuously collect telemetry?
No. The platform performs no background data collection. All diagnostics are executed on demand in response to explicit requests.
Is AI running on customer endpoints?
No. AI reasoning occurs centrally. Customer endpoints expose a controlled diagnostic interface only.
What audit logging is provided?
The platform records a complete audit trail for every diagnostic interaction, including query requested, data returned, timestamp, initiating user or process, endpoint identity, and AI reasoning context. Audit records are immutable and replayable.
Can customers review or export audit logs?
Yes. Audit logs are available for customer review, export, and integration with SIEM or governance tooling.
Is customer data used to train AI models?
No. Customer diagnostic data is not used for model training.
Compliance Packs
Documentation to support your compliance reviews and security assessments
HIPAA Security Brief
How Secronyx supports HIPAA compliance with zero data retention and read-only architecture.
Download PDFSOC 2 Type II Report
Independent audit of our security controls, availability, and processing integrity.
Request AccessThis platform does not ask for trust. It provides evidence.
Defensible, auditable, and enterprise-grade by design.