Trust center
Architecture and hardening
How the container is locked down and how it should be deployed.
The product ships as a desktop app for Windows, Mac and Linux and as one container image for servers. The browser does the analysis; the app or container only serves it. This page covers the container.
| Control | Detail |
|---|---|
| Non-root | The image runs as an unprivileged segaudit user |
| Least privilege | All Linux capabilities dropped |
| Immutable | Read-only root filesystem, /tmp on tmpfs |
| No data store | No database; evidence is never written to disk by the server |
| Browser protections | Content-Security-Policy, X-Content-Type-Options: nosniff, Referrer-Policy: no-referrer and X-Frame-Options: DENY on every response |
| Self-contained | Fonts and assets are bundled; no CDN or third-party requests |
| Pinned base | Base image pinned by digest |
Deployment guidance
- Bind to localhost or a management VLAN. Do not expose the app to the internet or to a plant process network.
- The app has no built-in authentication, by design, so put it behind your jump host’s access controls. Add TLS on a reverse proxy if several people share a host.
- Do not run it with host networking on a firewall management interface.
Known limits
The Content-Security-Policy allows inline styles (style-src 'self' 'unsafe-inline'), and Trusted Types are not yet enforced. Both are on the roadmap.
Last updated 2026-10-01.