Security

We are asking to run software inside your network

So this page states plainly what the agent can reach, what it may execute, what leaves your perimeter, and who on your side can see what. If any of it is unacceptable, better to know on day one.

Network

Outbound only

The agent opens connections to us. We never open connections to you. No inbound firewall rule is required or requested.

No standing access

The agent holds credentials you issue, scoped read-only, and can be revoked from your side at any time.

Scoped collection

Evidence is gathered for a specific incident and time window. The agent is not a continuous data pipe.

Data

Approved queries only

A finite, parameterised, row-capped catalogue that your team approves. Anything not in it does not execute — there is no free-text SQL path.

Redaction at the agent

Connection strings, bearer tokens, API keys, card numbers and personal data are removed before transmission. Redacting on ingest would already be too late.

Retention you set

Raw evidence expires well before the diagnosis that cites it. Both windows are yours to configure.

Access

Scoped roles

Access is bounded by environment and team, so production evidence and staging evidence are separate decisions.

Raw evidence is a separate grant

Seeing that an incident exists and seeing unredacted production rows are different permissions, deliberately.

Audit log

Who confirmed a diagnosis, who approved a query, who widened a scope, who disabled a redaction rule.

Where we are honest about our stage

Decim is early. Rather than imply certifications we do not hold, here is the current position: formal attestation is on the roadmap and not yet complete. The agent's permission model, query catalogue and redaction rules are available for your team to review before any pilot begins, and we would rather have that conversation first than last.

Get started

Send us your security questionnaire

We would rather answer it before a pilot than during one.