STING Security

Security That Matters

The STING Security Model

STING is built on a simple principle: your data stays yours. No cloud uploads. No telemetry. No “trust us” promises. Just software that runs on your hardware.

Local First

Your data never leaves your infrastructure. Period.

Encryption

AES-256 at rest, TLS 1.3 in transit

Privacy by Design

PII scrambling before AI processing

No Phone Home

Zero external calls after install


Security Features

Multi-Layer Encryption

  • AES-256 encryption at rest - All stored data is encrypted using industry-standard AES-256
  • TLS 1.3 in transit - All network communications use the latest TLS protocol
  • Encrypted Honey Jars - Knowledge bases remain encrypted from creation to consumption

PII Protection

  • Automatic PII detection - Names, addresses, SSNs, credit cards, and more
  • Pre-processing scrambling - Sensitive data is scrambled before AI sees it
  • Configurable sensitivity - Adjust protection based on your needs
  • Passkey-protected access - WebAuthn authentication for sensitive operations
  • Complete data sovereignty - Your data never leaves your infrastructure
  • Air-gap support - Run completely offline after initial install
  • Zero runtime dependencies - No phone-home, no telemetry, no external calls
  • Self-hosted only - You choose where your data lives
  • Network isolation - Sensitive processing can be completely isolated
  • WebAuthn passwordless - Modern, phishing-resistant authentication
  • Passkey support - Touch ID, Face ID, Windows Hello, hardware keys
  • Role-based access - Users get access to what they need
  • Ory Kratos - Battle-tested identity management
  • Action logging - Track what happens in your system
  • Export capabilities - Get your logs in standard formats
  • Local storage - Logs stay on your infrastructure

What We Don’t Do

No Cloud, No Tracking, No Exceptions

  • We don't collect telemetry
  • We don't phone home
  • We don't require license servers
  • We don't have "anonymous usage data"
  • We don't send anything anywhere after install

Open Source Security

STING is open source under the Apache 2.0 license. That means:

  • Full code visibility - Audit the code yourself
  • No hidden backdoors - Everything is transparent
  • Community review - Many eyes on the codebase
  • Fork if needed - Take it and run it yourself forever

Get Started Securely

Security from Day One

STING is secure by default. No special configuration needed. Install it and your data is protected.


Learn More