Security
10x is licensed software that runs in your network. Log content moves through your pipeline to your SIEM and never reaches log10x. A deployed engine has two outbound calls to log10x, and as shipped it makes neither.
-
What the software is, where it runs, and where log content goes.
-
The two calls, the three states, and what removes them.
-
Falsify each state with a packet capture of your own.
-
Every field a call can carry, typed, with a PII column.
-
Evaluation without an account, and how license keys are signed.
-
CycloneDX JSON per engine flavor, on every release.
Filling a SIG Lite, CAIQ or in-house questionnaire: the product answers are on these pages, and a form on your own paper comes back completed from security@log10x.com.
Report a vulnerability
Write to security@log10x.com, which is the address in security.txt. A first response comes within 24 hours.
| Remediation target, CVSS 9 and above | 48 hours |
| Remediation target, everything else | 30 days |
| Disclosure | Coordinated with the reporter, with recognition for valid findings |
Fixes ship as a new engine release, so applying one is an upgrade on your side. Every release from 1.1.73 carries an SBOM, which is what lets you scan the artifact you run against your own advisory feed.
Also useful
| Resource | What it is |
|---|---|
| Security FAQ | The same ground in question form, including deployment models and compliance |
| License | How the token works, and what happens without one |