Your security evidence stays in your cloud. Your keys never leave your KMS.
Yeti deploys inside your cloud account. Telemetry is compressed at the edge, written to your bucket, and encrypted with keys you control. Optional model-provider and support connections follow tenant policy; a disconnected topology keeps approved services inside the boundary.
Evidence processing and storage run inside your account.
Collection, processing, search, and retained evidence stay where the data lives. Optional model, support, update, and connector paths are explicit, tenant-policy governed, and topology-specific.
Four controls, and every one of them is yours to hold.
Cloud-native identity, no shared secret
Supported cloud paths use short-lived, scoped workload identity such as IRSA, GCP Workload Identity, or Azure Managed Identity. Other topology-specific secrets and provider credentials remain explicit evaluation items.
Your keys, generated and revoked by you
Every chunk is encrypted at rest with a key you create and rotate in your own KMS. Revoke it and the archive goes dark on your command, with no support ticket and no vendor in the loop.
Encrypted end to end
Data is encrypted at rest with your KMS key and in transit with TLS. The bytes are protected from the edge where they are collected to the bucket where they come to rest.
Zero-egress option
For classified and sovereign estates, Yeti can use a disconnected topology in which telemetry, retrieval, detection, and approved model services remain inside the customer boundary.
Built for the buyers who cannot move their data.
Regulated buyers evaluate residency, key custody, access, evidence retention, and outbound dependencies against their own obligations. Yeti’s customer-controlled patterns can support that evaluation; the deploying organization and its assessor determine compliance.
Keep every security signal. Keep it in your cloud.
Tell us what your environment looks like and we will map the deployment to your cloud, your keys, and your residency requirements.