Security claims should be verifiable, not decorative.
Log Intelligence is designed for private incident investigation in customer-controlled infrastructure. This page separates implemented controls, release-verification workflow and customer responsibilities so security teams can review the product without relying on unsupported certification claims.
Implemented buyer-review controls
A practical enterprise trust package around the forensic workflow.
These controls are designed to answer the questions security, platform and procurement teams usually ask before a pilot or production deployment.
Private evidence boundary
Incident evidence is analysed inside the customer-managed Docker deployment. CloudBridgeIT licensing does not require uploaded incident logs, and Enterprise can operate with an air-gapped activation workflow.
Enterprise identity boundary
Enterprise supports SAML/OIDC-backed sign-in through a customer-controlled identity-aware reverse proxy. Trusted identity headers are accepted only when proxy trust and the shared proxy secret are explicitly configured.
Tamper-evident audit evidence
New audit events are SHA-256 hash chained. Authenticated administrators can validate chain integrity and export audit evidence as JSON or CSV for review.
Immutable RCA decision record
The Decision & Approval Ledger preserves each RCA conclusion, evidence snapshot, rejected hypotheses, reasoning, approvals and corrective actions as a new SHA-256 chained version. Signed .li-case exports cover the complete ledger.
Release supply-chain controls
The production publication workflow builds multi-architecture images, generates OCI SBOM and provenance attestations, gates HIGH/CRITICAL vulnerabilities with Trivy, and signs pushed digests using Sigstore Cosign.
Hardened container runtime
Recommended Compose deployment uses a non-root runtime, no-new-privileges, dropped Linux capabilities, a read-only root filesystem, temporary /tmp storage and a PID limit.
Procurement documentation
Security architecture, data-flow, reverse-proxy SSO, customer deployment and support/SLA guidance are maintained with the Docker release so technical and procurement reviews use the same operating model.
Identity & access
Keep authentication at your enterprise boundary.
The Enterprise SSO design does not embed a second identity platform inside the incident product. A customer identity-aware proxy terminates SAML or OIDC, enforces the organisation's IdP policy, and forwards trusted identity only across an explicitly configured application boundary.
Export evidence that can be reviewed outside the application.
New audit events are chained with SHA-256 hashes so administrators can test whether the recorded sequence remains intact. Authenticated JSON and CSV exports provide a portable review trail for internal assurance, customer review or audit preparation.
Measure the investigation, not a marketing estimate.
Pilot outcome snapshots capture measurable investigation outputs that can be compared with the organisation's normal incident-review baseline. This avoids inventing universal time or cost savings.
Release assurance
The pipeline can produce assurance artefacts. The registry digest still has to prove them.
The production publishing workflow is configured for SBOM, provenance, vulnerability policy and image signing. A source package or local build is not labelled as registry-verified merely because that workflow exists.
OCI software bill of materials generated during production publication.
Maximum-level build provenance attached to the published image.
Trivy policy blocks publication on HIGH/CRITICAL findings under the configured release policy.
The pushed digest is signed keylessly through Sigstore OIDC in the production workflow.
Before production procurement, verify the actual published registry digest, signature and attestations. This site does not mark an image as signed or scanned merely from source-package metadata.
Shared responsibility
What the customer still controls.
Enterprise readiness also depends on the environment in which Log Intelligence runs. Production review should include network segmentation, TLS termination, backup and recovery for the persistent data volume, identity-provider policy, connector credentials, registry verification and retention requirements.
Bring security and operations into the pilot from day one.
Review the data boundary, identity model, audit evidence, deployment controls and measurable pilot outcomes before expanding beyond the first investigation team.