SECURITY

The agent gets governed tools, not network access.

ConvergeSense separates cloud identity and policy from onsite credentials and device sessions. The commercial remote surface is read-only.

Boundary

  • The Engine initiates outbound connections; no inbound equipment port is required.
  • Equipment credentials and raw terminal or API sessions remain onsite.
  • Only bounded normalized results, provenance, and sanitized execution metadata cross to the control plane.
  • Every invocation is checked against tenant membership, OAuth grant, role, policy, entitlement, and exact connector digest.

Execution safety

The gateway enforces reviewed schemas, limits, freshness, rate limits, and idempotency. ConvergeSense does not replay a transmitted device command after an ambiguous failure. Connector output is treated as untrusted data, never as an instruction or executable argument.

Encryption and retention

Transport uses TLS. Classified onsite cache entries use authenticated encryption. Normalized job results expire after 15 minutes, agent tool-call metadata after 90 days, and security audit events after one year unless a customer agreement specifies a different supported retention period.

Incidents and vulnerabilities

Report suspected vulnerabilities to security@convergesense.com. Include the affected hostname, time, and safe reproduction details; never email credentials or raw customer data. We triage reports, contain affected access, preserve audit evidence, notify impacted customers when required, and publish remediation guidance appropriate to the incident.