Docs
Security model
Read-only roles, running in your cluster, no phone-home, what leaves your estate, and how the two-model check works.
On this page
A security tool asks for trust. This page sets out what Firekeeper can reach, where it runs, and what leaves your estate, so you can decide how much trust to give it.
Read-only roles
Watch reads through roles that you create in your own AWS accounts. Those roles are read-only. Firekeeper holds no permission you did not grant, and you can read every permission it holds in your own account.
Because the roles do not allow writes, Watch cannot change your resources even if something inside Firekeeper went wrong. The limit is enforced by your cloud, not by a promise in our code.
Setup is the one step that needs more: an operator with admin rights creates the roles and installs the hub. After setup, Firekeeper runs with the read-only roles alone.
It runs in your cluster
Firekeeper is self-hosted. The hub runs as a workload inside your own EKS cluster. There is no hosted service on our side that reads your estate.
No phone-home
Firekeeper does not call back to us.
- No telemetry. It sends no usage, metrics or crash reports to us.
- No online license check. A license is a signed file. Firekeeper verifies the signature offline when it starts, against public keys built into the product.
- No key fetching. We publish our public keys at
/.well-known/firekeeper/license-keys.jsonso you can check a license yourself. The product will carry the same list and will never fetch it.
What leaves your estate
| What | Where it goes |
|---|---|
| Reads of your accounts and clusters | Made from inside your estate, through your roles. |
| Material needed to write up and check findings | Sent to the two AI models that write and check the report. |
| Telemetry, usage data, license checks | Not sent. There are none. |
| Anything at all | Never sent to firekeeper.sh or to us. |
The write-up step is the one place where data leaves your estate. Exactly what is sent to the models will be documented in full before the first release.
How the two-model check works
Findings come from rules, not from a model. The models only write them up.
- Rules turn evidence into findings, each linked to the records that prove it.
- One AI model writes up the findings.
- A second model, from a different maker, reads the write-up against the findings. Its only job is to refute the first.
- If the check fails, the report falls back to the rules alone.
Rules decide what is a finding. The models only write them up. When the check fails, the report is the rules’ own findings, each with the records that prove it.
Defend, when it exists
Defend is in development and not built. When it ships it will be optional and off by default. Each action will be reversible, signed by an operator and recorded.
This website
This site has its own short security page: no trackers, no third-party requests, sign-in with passkeys only, and signed licenses. See Security.