Discovery without content
Inventory, identity, package, process, configuration and egress metadata. Prompts and responses are not collected or stored.
This inventory separates what is detected locally, what is transmitted, what is retained, what can leave through an integration and what Araghatta never collects by default.
A security team can trace each finding from collection through storage, analyst access and export without relying on a vague “metadata only” promise.
01 · DEVICEDetect locallyBounded collectors identify AI assets, secrets, processes, configuration and egress. Redaction happens before spooling.02 · TRANSPORTTransmit minimallyStructured, redacted findings over authenticated TLS. No raw secret, prompt, response or packet payload.03 · CONTROL PLANEStore by tenantEncrypted records are region-bound, retention-controlled and isolated by deployment tier and tenant policy.04 · ANALYSISScore with boundariesDeterministic scoring is always available. Optional reasoning uses the customer-approved model and region.05 · CUSTOMER STACKExport deliberatelyOnly approved fields reach SIEM, SOAR, ITSM, webhook or evidence packages; every export is audited.Cloud attack-path analysis uses structured host and control-plane attributes. It does not retrieve temporary credentials, read storage objects or execute exploit traffic.
| Evidence class | Fields used | Excluded |
|---|---|---|
| AI agent runtime | Process/package identity, service or container, owner, unattended state, bounded tool capabilities and network context | Prompt/response bodies, arbitrary file contents and usable secret values |
| Cloud workload | Provider, account/project/subscription, region, instance/resource ID, image, tags and workload identity reference | Memory dumps, packet payloads and unrelated application data |
| Metadata service | Provider, mode/version requirement, hop limit, endpoint state and observed local reachability result | Credential documents, session tokens and harvested identity material |
| Identity & policy | Role/service-account/managed-identity ID, trust relationship, effective actions, resource scope, conditions and privilege edges | Private keys, access-key values, OAuth tokens and authentication cookies |
| Storage posture | Bucket/account name or resource ID, policy/ACL posture, public-access controls, encryption, logging, versioning, tags and reachable action classes | Object bodies, object downloads and customer content |
| Derived attack path | Ordered preconditions, evidence references, confidence, blast radius, severity, remediation and verification status | Exploit payloads, credential replay and destructive validation |
Tenant policy can further suppress identities, paths, command-line fragments, network fields and retention. The default is the minimum necessary for AI-security decisions.
| Data class | Detected locally | Transmitted & stored | Transformation | Never collected by default |
|---|---|---|---|---|
| Device & operating system | Device identity, hostname, OS, build, architecture, management posture | Tenant-scoped device ID, selected host attributes, sensor health and last-seen time | Hostname can be tokenised; IP storage can be disabled | Device files unrelated to bounded collectors |
| User & service identity | Interactive user, service account, session and directory context | Account identifier, identity type, organisation context and owner mapping | Pseudonymisation and role-scoped display available | Passwords, authentication tokens and personal communications |
| Process & execution | Image, parent, signer, hash, version and command line | AI-relevant process metadata and execution state | Tokens, passwords, bearer strings and secret shapes redacted on-device | Process memory, screen content and unrelated command histories |
| Network & egress | Destination hostname/IP, port, protocol, process and time | AI-provider destination, source asset, connection metadata and policy result | IP and hostname retention are tenant-configurable | Packet payload, prompt body, response body and browser history |
| AI applications, CLIs & SDKs | Name, package, version, publisher, path class and runtime state | Normalized product, version, owner, sanction status and evidence | Paths can be reduced to location class | Application data, project source code and model conversations |
| MCP servers, agents & skills | Package, version, source, configuration location, tool scope and runtime | Normalized asset, provenance, permissions, identity and risk evidence | Configuration values are stripped; only approved metadata leaves the device | Credential values, tool-output content and arbitrary repository files |
| API keys & secrets | Provider pattern, location and usable value for local matching only | Provider, one-way fingerprint, location class, exposure reason and rotation status | Fingerprinting and masking occur before disk spool or network transmission | Usable secret, private-key material, password or full token |
| IDE & browser extensions | Stable ID, name, publisher, version and account class | Extension identity, user/device mapping, sanction state and risk | Account can be pseudonymised | Page content, browsing history, cookies, form data and messages |
| Cloud assets & identities | Organisation hierarchy, resource, service, configuration, IAM and region | Selected resource and policy metadata, ownership, exposure and evidence | Resource names and tags can be suppressed or tokenised | Object bodies, database rows, model prompts/responses and secret values |
| Workloads & AI-BOM | Image packages, models, AI libraries, runtime, workload identity and egress | Package/version, CVE, model/provider, workload owner and runtime state | Ephemeral instances deduplicated to workload identity | Container filesystem bodies and customer application source |
| Policy, response & exceptions | Local or gateway policy decision and user response where enabled | Policy, action, target, decision, approver, reason, time and rollback state | Role-scoped, immutable audit representation | Unrelated employee activity or productivity scoring |
The endpoint discovery sensor stays metadata-focused. Content inspection is enabled only through a customer-approved policy enforcement point with an explicit data classification and retention contract.
Inventory, identity, package, process, configuration and egress metadata. Prompts and responses are not collected or stored.
When enabled, the approved policy engine classifies content in the selected enforcement point and returns allow, warn, redact or block.
The retained record contains class, rule, action, actor and reason. Raw content retention is off by default and can remain disabled.
Reasoning adds advisory context; it does not replace authoritative CVE severity, deterministic risk policy or a customer’s approval process.
| Mode | Data sent | Region & processor | Training & retention | Failure behavior |
|---|---|---|---|---|
| Deterministic only | No finding data sent to a reasoning model | Runs inside the selected control plane | No model training or model-side retention | Scoring and policy continue without AI reasoning |
| Araghatta managed reasoning | Redacted finding fields required for explanation and correlation | Customer-selected supported region and contracted subprocessor | No customer-data training; provider retention disabled where supported | Falls back to deterministic scoring and queues advisory analysis |
| Customer model / private inference | Customer-selected fields through the customer-controlled endpoint | Customer VPC, Bedrock/Azure OpenAI/Vertex or local inference | Controlled by the customer’s model contract and tenant policy | Deterministic operation remains available |
Default retention is documented in the order form and tenant configuration; regulated deployments can set field-class and region-specific policies.
Findings, raw events, audit evidence, inactive assets and exports can use different retention windows.
RBAC, SSO, SCIM, scoped support access and field-level views determine who can see identity and evidence.
API/UI deletion, offboarding export, documented deletion SLA and backup-expiry behavior.
Legal holds are separately authorised, auditable and restricted to the required tenant and record classes.
We provide the machine-readable field dictionary, architecture, DPIA support, subprocessor list, retention schedule and sample exports before production rollout.