Skip to content

Security and data retention

The application and its APIs are available over HTTPS. Each user signs in with their own account; their organization permissions determine which operations are available.

Enable multifactor authentication and review access when your team changes. The Reader role allows users to view and export logs: assign it only to people allowed to keep a copy.

ConnectionTransport protection
Application and APIs over HTTPSEncrypted connection.
Syslog over UDPUnencrypted messages; no delivery confirmation.
Syslog over TCPAn established server connection, but unencrypted messages.
Syslog over TLS, when configured for the locationEncrypted connection using a dedicated TLS destination and port.

The UDP/TCP port shown for a location does not become a TLS port just by changing the device’s protocol. If you require TLS, ask support for the settings available for that location, then configure certificate validation on the sender.

Allowed IP addresses filter the sources that can send logs. They do not encrypt messages or replace application access permissions.

Source log retention is described in Archiving and retention. Each file’s Expires date shows its availability in the application.

ZIP files prepared by a period export have their own expiration date. An already issued download link may remain usable until it expires; treat it as confidential. Once downloaded, a copy is subject to your own storage and deletion rules.

Audit logs record events captured by the application, including configuration changes and export operations. They are separate from your devices’ syslogs. Issuing a download link does not prove that the browser received the entire file.

For a supplier questionnaire, ask support for the documents applicable to your service: hosting location, subprocessors, encryption at rest, backups, deletion procedures and service commitments. Verify contractual guarantees and any attestations in those documents.

Your team determines what data to collect, who may access it and how long it must be retained. Avoid sending passwords, tokens or other secrets in logs.