Signed releases
Every node image and update is signed, and a node refuses anything it cannot verify. Each release ships with a software bill of materials.
Trust Center·Updated September 2026
How we build Kybernao, where your data lives, what can leave your site, and how to reach us about a vulnerability. Documents that need an NDA are one request away.
The controls below are part of the product and of how our own team works. Your security review can check each one against a running node.
Every node image and update is signed, and a node refuses anything it cannot verify. Each release ships with a software bill of materials.
Node keys live in the hardware root of trust on the node. Kybernao staff hold no standing credentials for customer nodes.
Support happens in a time-boxed session your operator opens, and every command in it lands in your ledger.
Data is encrypted at rest on the node and in transit between nodes, sensors and your integrations.
Code changes need a second engineer, and the release pipeline runs in isolated build infrastructure.
We run Red against our own environment on the same cadence we recommend to customers, and fix what it proves.
Everything Kybernao learns about your environment is stored on the node inside your site. Nothing leaves unless you switch on a data class, and each object that does leave is written to the egress ledger first.
| Data class | Stored on the node | Can leave the site | Default |
|---|---|---|---|
| Findings and evidence | Yes | To your SIEM or FedSpace, when enabled | Off |
| Audit events | Yes, signed | To your SIEM, when enabled | Off |
| Terrain graph | Yes | Selected state to peer nodes, or to Kybernao Cloud, through FedSpace | Off |
| Raw OT capture | Yes, time-limited | No egress path | Never |
| Controller project files and live tag values | Yes | No egress path | Never |
| Credentials and keys | In the hardware root | No egress path | Never |
Ask for any of these and we will send them, or walk your team through them live. Some are shared under an NDA.
We welcome reports from researchers and customers, and we will not pursue anyone who follows this policy in good faith.
Describe the issue, the affected product or page, and the steps to reproduce it. Encrypt it if you prefer, and ask us for a key.
A security engineer replies to confirm we have it, then keeps you updated while we investigate and fix.
Once a fix ships we tell you, and with your permission we credit you in the release notes.
Not by default. Staff hold no standing credentials. If you need help, your operator opens a time-boxed support session, and every action taken in it is recorded in your ledger.
No. Models that learn from your environment run and stay on your node. Nothing from your site is pooled with other customers.
Signed update bundles can be carried in on approved media. The node verifies the signature before installing, exactly as it would online.
No. Kybernao Cloud is an optional hosted peer that a node can federate to. Everything on this page, and every product capability, works with it switched off, which is the default.
Yes. Request it above and we will send the SBOM for the current release, usually alongside the architecture document.
Email security@kybernao.ai. Customers also have a named mission engineer who can open an incident bridge directly.
Bring your questionnaire. We will answer it live against a running node.