Blackhount Watch Attack Surface Monitoring and Agent Security protect continuous monitoring data — assets, findings, changes, agent inventory, credentials, and customer workspaces — through layered identity, access, isolation, and recovery controls.
Blackhount protects the integrity and availability of the records that determine security posture and agent capability risk: monitored assets, scan findings, configuration and exposure changes, technology signals, enrolled endpoints, detected agents and MCP servers, tools, permissions, and enrollment credentials.
Sign-in supports password authentication with optional multi-factor authentication (TOTP). Access is role-based across admin, member, and viewer permissions. Authorization checks run server-side on application APIs. Sessions use HttpOnly cookies with Secure and SameSite controls, expire on a configured lifetime, and are cleared on sign-out. Sensitive authentication paths are rate-limited.
Organization records are separated at the application and data-access layers. Watch APIs and Agent Security APIs resolve the tenant from the authenticated session or API key and scope queries to that organization. Automated tests verify tenant-scoped access for assets, findings, agent endpoints, components, and related records so users cannot retrieve another organization’s monitoring data.
Attack Surface Monitoring preserves relationships between assets, findings, severity, remediation guidance, and change history. Agent Security preserves provenance for enrolled endpoints, snapshots, components, capabilities, findings, and configuration changes. Significant Agent Security actions such as enrollment token and endpoint credential revocation create auditable operational records with actor, action, object, and timestamps where implemented.
Agent Security continuous upload uses per-endpoint credentials that are stored hashed, can be rotated by re-issuing credentials, and can be revoked to disconnect an endpoint. Enrollment tokens are one-time and revocable. Agent Check itself is local-first and does not upload data unless a workspace intentionally enrolls an endpoint.
Traffic to Blackhount services is protected with TLS encryption in transit. Application data for Watch and Agent Security is stored in managed cloud services. Secrets and credentials are maintained outside source code and handled through secure runtime configuration.
Blackhount maintains documented backup and restore procedures covering application-database restore and post-restore verification of sign-in, organization access, Attack Surface Monitoring data access, Agent Security endpoint and inventory access, and core operational flows when in scope.
Operational practices include rate limiting on sensitive authentication paths, review of suspicious authentication activity, documented incident handling, production change control, customer offboarding, and data export and deletion workflows. Agent Security authorization boundaries keep continuous upload credentials and dashboard sessions separate. Dependency monitoring and access review follow internal operational runbooks.
Blackhount’s security program is organized around controls commonly evaluated for security, availability, and confidentiality during enterprise assurance reviews. Blackhount provides accurate information about implemented controls, testing status, and independent assessment status during customer procurement. Blackhount does not claim certifications that have not been completed.
| Area | Current status |
|---|---|
| Multi-factor authentication (TOTP) | Implemented |
| Role-based access control | Implemented |
| Tenant-isolation testing | Implemented and tested |
| HttpOnly Secure SameSite sessions | Implemented |
| Auth rate limiting | Implemented |
| Agent enrollment token revoke | Implemented |
| Per-endpoint credential hashing | Implemented |
| Endpoint credential revocation | Implemented |
| Attack Surface / Agent Security API isolation | Implemented |
| Backup and recovery | Documented restore procedures |
Attack Surface Monitoring owns internet-facing asset monitoring, findings, exposure detection, configuration and security-change visibility, and technology intelligence — answering what attackers can reach.
Agent Security owns enrolled-endpoint discovery and continuous monitoring of AI agents, MCP servers, tools, permissions, capabilities, and agent-side changes — answering what your AI can reach. Free Agent Check remains local-first until a workspace enrolls an endpoint on Watch Pro.