Security & Trust

Your credentials stay local. Your network data is anonymized.

Rezonance separates device access, read-only reasoning and production change into distinct security boundaries. Rez can investigate and recommend. Netcode can execute only through an approved change workflow.

Customer-side credentialsPasswords, keys and API tokens remain with the local runner.
Anonymized reasoning dataSensitive network identifiers are transformed before Rez reasoning.
Read-only diagnosticsRez has no configuration-write action family.
Human-approved automationNetcode waits at the production write boundary.

Privacy before reasoning

Operational context without exposing network identity.

Rez preserves the relationships needed for routing and topology analysis while replacing sensitive identifiers before they reach the reasoning layer.

IP addressing

AES-128 prefix-preserving tokenization

Management, interface, next-hop and peer addresses are transformed while prefix relationships remain usable for network analysis.

Device identity

Hostnames and MAC addresses are mapped

Known device names and MAC addresses are replaced with deterministic session mappings. SNMP community strings are irreversibly redacted.

Controlled return path

Results are restored for the authorized engineer

The customer-facing response is mapped back inside the controlled session so engineers can act on familiar device identities without exposing them to the reasoning layer.

Customer-side evidenceBRANCH-204 · peer 10.44.8.1 · 00:1c:73:aa:4e:19
Anonymize →
Reasoning contextDEVICE-4821 · peer 44.27.150.11 · 68:0d:c2:55:31:9c

Customer trust boundary

Device access stays inside your network.

The local Windows or Linux runner initiates one outbound connection to Rezonance and performs device SSH/API work from inside the customer environment.

Customer network

Local runner and credential vault

Discovers devices, resolves credentials, opens SSH/API sessions and executes approved jobs locally.

OUTBOUND TLS 443No inbound firewall rule
Rezonance cloud

Control, reasoning and audit

Netcode plans and governs work. Rez analyzes anonymized read-only evidence. Audit records retain the accountable workflow.

Two action families

Read-only investigation is not a path to write.

The shared runner supports both products, but the action boundary is enforced in code. Rez cannot invoke Netcode's write handlers.

Rez Diagnostics

Allowlisted, auditable and fail-closed

Read commands pass through command and pipe-filter policy, quotas and runner routing. If safety or runner execution is unavailable, the request fails rather than opening a direct path.

Netcode Automation

Exact preview before production

Generated commands, rollback, policy checks and first-device proof appear before the production decision. Apply remains a separate human-approved action.

Netcode Shell

Human-operated, attributed access

Interactive SSH remains a distinct engineer-operated surface. Sessions are attributed and recorded instead of being presented as Rez automation.

Controls

Security controls follow the work from discovery to rollback.

Prefix-preserving IP anonymization
Hostname, MAC and secret redaction
Runner-local device credentials
Outbound-only runner connection
Read-only Rez action family
Fail-closed command safety
Per-investigation budgets and quotas
Human approval before Netcode writes
Commands, verification and rollback audit
Signed integration and webhook boundaries
Cross-incident context isolation
No foundation-model training on customer data

Compliance and assurance

Rezonance is building its formal security and privacy program for enterprise requirements. We do not claim certifications that have not been completed. Contact us for current architecture details, deployment controls and assurance roadmap.