Skip to content

Security

10x is licensed software that runs in your network. Log content moves through your pipeline to your SIEM and never reaches log10x. A deployed engine has two outbound calls to log10x, and as shipped it makes neither.

  • Product shape

    What the software is, where it runs, and where log content goes.

  • Outbound

    The two calls, the three states, and what removes them.

  • Verifying

    Falsify each state with a packet capture of your own.

  • Telemetry

    Every field a call can carry, typed, with a PII column.

  • Operations

    Evaluation without an account, and how license keys are signed.

  • SBOM

    CycloneDX JSON per engine flavor, on every release.

Filling a SIG Lite, CAIQ or in-house questionnaire: the product answers are on these pages, and a form on your own paper comes back completed from security@log10x.com.

Report a vulnerability

Write to security@log10x.com, which is the address in security.txt. A first response comes within 24 hours.

Remediation target, CVSS 9 and above 48 hours
Remediation target, everything else 30 days
Disclosure Coordinated with the reporter, with recognition for valid findings

Fixes ship as a new engine release, so applying one is an upgrade on your side. Every release from 1.1.73 carries an SBOM, which is what lets you scan the artifact you run against your own advisory feed.

Also useful

Resource What it is
Security FAQ The same ground in question form, including deployment models and compliance
License How the token works, and what happens without one