Security Architecture

Platform Security

Learn how TattvaLens protects customer cloud environments through agentless scanning, read-only IAM access, encrypted data handling, and enterprise-grade operational security.

Last updated: October 15, 2024

Agentless Architecture
Read-only IAM Access
AES-256 Encryption
No Infrastructure Changes

How It Works

A completely agentless flow designed to gather metadata without modifying your AWS environment or impacting production workloads.

Customer AWS Account

Your secure cloud infrastructure

Read-only IAM Role

Tattvora Ingest

Securely collects configuration metadata over TLS 1.3

Inventory Graph

LENS Intelligence Engine

Analyzes configuration state for security and cost optimizations

Platform Dashboard

Actionable insights presented securely to your team

Security Principles

Agentless Architecture

No agents to install, maintain, or update. We connect directly to the AWS API, ensuring zero impact on your production workloads' performance or stability.

Least Privilege

We operate strictly via Cross-Account IAM Roles with explicit read-only policies. We can only view metadata, never customer data within databases or object storage.

Encryption by Default

All data in transit is secured using TLS 1.3. Any cached metadata at rest is encrypted using AES-256 block-level encryption within our secure multi-tenant environment.

Customer Data Ownership

Your cloud infrastructure belongs to you. We strictly process structural metadata and retain it only as long as necessary to provide platform functionality.

Information Security

  • Zero-Trust Architecture: Our internal systems require cryptographic verification for all service-to-service communication.
  • Secure Development Lifecycle (SDLC): All code deployments are peer-reviewed and scanned by automated SAST/DAST tools before reaching production.
  • Vulnerability Management: Dependencies and container images are scanned continuously. Critical patches are applied within strict SLAs.

Data Protection

  • Metadata Isolation: Customer metadata is logically separated. Our multi-tenant architecture enforces strict boundaries preventing cross-tenant access.
  • Data Retention: Assessment logs and temporary configuration caches are automatically purged according to our data retention policy.
  • No PII in Telemetry: We aggressively filter our application telemetry to ensure no customer infrastructure names or IP addresses leak into external logging tools.

IAM & Access Model

  • Role-Based Access Control (RBAC): Within the TattvaLens platform, you can restrict which team members can view executive reports or trigger new assessments.
  • Audit Logging: All assessment triggers and IAM assumption events are logged and can be exported to your SIEM via CloudTrail.

Responsible Disclosure

We take security seriously. If you believe you have found a security vulnerability in TattvaLens, please do not disclose it publicly. Contact our security team immediately, and we will work with you to resolve the issue promptly in accordance with industry best practices.

Need Security Documentation?

We provide comprehensive resources for enterprise procurement and compliance teams:

  • Architecture Overview
  • IAM Permissions
  • Compliance Questionnaire
Contact Security Teamsecurity@tattvora.app