Docs

Security model

Read-only roles, running in your cluster, no phone-home, what leaves your estate, and how the two-model check works.

On this page

A security tool asks for trust. This page sets out what Firekeeper can reach, where it runs, and what leaves your estate, so you can decide how much trust to give it.

Read-only roles

Watch reads through roles that you create in your own AWS accounts. Those roles are read-only. Firekeeper holds no permission you did not grant, and you can read every permission it holds in your own account.

Because the roles do not allow writes, Watch cannot change your resources even if something inside Firekeeper went wrong. The limit is enforced by your cloud, not by a promise in our code.

Setup is the one step that needs more: an operator with admin rights creates the roles and installs the hub. After setup, Firekeeper runs with the read-only roles alone.

It runs in your cluster

Firekeeper is self-hosted. The hub runs as a workload inside your own EKS cluster. There is no hosted service on our side that reads your estate.

No phone-home

Firekeeper does not call back to us.

  • No telemetry. It sends no usage, metrics or crash reports to us.
  • No online license check. A license is a signed file. Firekeeper verifies the signature offline when it starts, against public keys built into the product.
  • No key fetching. We publish our public keys at /.well-known/firekeeper/license-keys.json so you can check a license yourself. The product will carry the same list and will never fetch it.

What leaves your estate

WhatWhere it goes
Reads of your accounts and clustersMade from inside your estate, through your roles.
Material needed to write up and check findingsSent to the two AI models that write and check the report.
Telemetry, usage data, license checksNot sent. There are none.
Anything at allNever sent to firekeeper.sh or to us.

The write-up step is the one place where data leaves your estate. Exactly what is sent to the models will be documented in full before the first release.

How the two-model check works

Findings come from rules, not from a model. The models only write them up.

  1. Rules turn evidence into findings, each linked to the records that prove it.
  2. One AI model writes up the findings.
  3. A second model, from a different maker, reads the write-up against the findings. Its only job is to refute the first.
  4. If the check fails, the report falls back to the rules alone.

Rules decide what is a finding. The models only write them up. When the check fails, the report is the rules’ own findings, each with the records that prove it.

Defend, when it exists

Defend is in development and not built. When it ships it will be optional and off by default. Each action will be reversible, signed by an operator and recorded.

This website

This site has its own short security page: no trackers, no third-party requests, sign-in with passkeys only, and signed licenses. See Security.