Docs
FAQ
Short answers to the questions people ask first.
On this page
- Can I install it today?
- What does it cost?
- Does it change anything in my accounts?
- Where does it run?
- Which clouds does it cover?
- Does it phone home?
- Does any data leave my estate?
- What do the AI models do?
- How many installs do I need?
- What happens if I retire a license?
- How do I check a license file?
- How do I sign in?
- How do I report a security problem?
Can I install it today?
No. Firekeeper is not released. There is no installer, image or release yet. The install command works, but it only prints the status. See Install.
What does it cost?
Nothing today. The one plan, community, is free and includes Watch for 365 days.
Does it change anything in my accounts?
Not in Watch, which is the default. Watch reads through read-only roles you create, so it cannot change your resources. Defend, which would take a small set of reversible actions, is optional and in development.
Where does it run?
Inside your own EKS cluster, under roles you create. There is no hosted service on our side that reads your estate.
Which clouds does it cover?
AWS accounts and Kubernetes on EKS.
Does it phone home?
No. There is no telemetry and no online license check. A license is a signed file that Firekeeper verifies offline when it starts.
Does any data leave my estate?
Yes, one kind: the material needed to write up and check findings goes to the two AI models that write and check the report. Nothing goes to us. See What leaves your estate.
What do the AI models do?
Rules decide what is a finding. The models only write them up. A second model, from a different maker, tries to refute the write-up. If the check fails, the report falls back to the rules alone, with their proof attached. See How the two-model check works.
How many installs do I need?
One per estate. An estate is one AWS organization and the EKS clusters in it. One hub watches the whole estate, and each estate needs its own license.
What happens if I retire a license?
It is marked as retired in the dashboard. Because a license is checked offline, the file itself keeps working until it expires.
How do I check a license file?
Paste it into the verify page. The check runs in your browser against our published public keys. Nothing is uploaded.
How do I sign in?
With a passkey. There are no passwords. When you sign up you also get eight one-time recovery codes. Keep them somewhere safe.
How do I report a security problem?
Email support@firekeeper.sh. See Security.