Security built for monitoring-critical records

Blackhount Watch Attack Surface Monitoring and Agent Security protect continuous monitoring data — assets, findings, changes, agent inventory, credentials, and customer workspaces — through layered identity, access, isolation, and recovery controls.

Security built into the monitoring record

Blackhount protects the integrity and availability of the records that determine security posture and agent capability risk: monitored assets, scan findings, configuration and exposure changes, technology signals, enrolled endpoints, detected agents and MCP servers, tools, permissions, and enrollment credentials.

Identity and access protection

Sign-in supports password authentication with optional multi-factor authentication (TOTP). Access is role-based across admin, member, and viewer permissions. Authorization checks run server-side on application APIs. Sessions use HttpOnly cookies with Secure and SameSite controls, expire on a configured lifetime, and are cleared on sign-out. Sensitive authentication paths are rate-limited.

Tenant isolation

Organization records are separated at the application and data-access layers. Watch APIs and Agent Security APIs resolve the tenant from the authenticated session or API key and scope queries to that organization. Automated tests verify tenant-scoped access for assets, findings, agent endpoints, components, and related records so users cannot retrieve another organization’s monitoring data.

Monitoring integrity and accountability

Attack Surface Monitoring preserves relationships between assets, findings, severity, remediation guidance, and change history. Agent Security preserves provenance for enrolled endpoints, snapshots, components, capabilities, findings, and configuration changes. Significant Agent Security actions such as enrollment token and endpoint credential revocation create auditable operational records with actor, action, object, and timestamps where implemented.

Agent Security continuous upload uses per-endpoint credentials that are stored hashed, can be rotated by re-issuing credentials, and can be revoked to disconnect an endpoint. Enrollment tokens are one-time and revocable. Agent Check itself is local-first and does not upload data unless a workspace intentionally enrolls an endpoint.

Data protection

Traffic to Blackhount services is protected with TLS encryption in transit. Application data for Watch and Agent Security is stored in managed cloud services. Secrets and credentials are maintained outside source code and handled through secure runtime configuration.

Backup and recovery

Blackhount maintains documented backup and restore procedures covering application-database restore and post-restore verification of sign-in, organization access, Attack Surface Monitoring data access, Agent Security endpoint and inventory access, and core operational flows when in scope.

Security operations

Operational practices include rate limiting on sensitive authentication paths, review of suspicious authentication activity, documented incident handling, production change control, customer offboarding, and data export and deletion workflows. Agent Security authorization boundaries keep continuous upload credentials and dashboard sessions separate. Dependency monitoring and access review follow internal operational runbooks.

Compliance approach

Blackhount’s security program is organized around controls commonly evaluated for security, availability, and confidentiality during enterprise assurance reviews. Blackhount provides accurate information about implemented controls, testing status, and independent assessment status during customer procurement. Blackhount does not claim certifications that have not been completed.

Current security status

AreaCurrent status
Multi-factor authentication (TOTP)Implemented
Role-based access controlImplemented
Tenant-isolation testingImplemented and tested
HttpOnly Secure SameSite sessionsImplemented
Auth rate limitingImplemented
Agent enrollment token revokeImplemented
Per-endpoint credential hashingImplemented
Endpoint credential revocationImplemented
Attack Surface / Agent Security API isolationImplemented
Backup and recoveryDocumented restore procedures

Two security surfaces, clear boundaries

Attack Surface Monitoring owns internet-facing asset monitoring, findings, exposure detection, configuration and security-change visibility, and technology intelligence — answering what attackers can reach.

Agent Security owns enrolled-endpoint discovery and continuous monitoring of AI agents, MCP servers, tools, permissions, capabilities, and agent-side changes — answering what your AI can reach. Free Agent Check remains local-first until a workspace enrolls an endpoint on Watch Pro.

[email protected] · Contact · Sign in to Watch