Self-hosted open-source apps for CISOs: controls, evidence and audit trail

Private networking, named access, tracked advisories and an audit trail you can export to your SIEM. Every control is written down, and the evidence is available before you sign.

Start with one workloadBook a 30-minute briefing

Network
Private mesh, one hardened gate on port 443
Access
Named engineers, least privilege, every session logged
Audit trail
Exportable to your SIEM
Framework
Built to ISO 27001 controls

The questions a CISO asks first

Your review starts with attack surface, access and evidence. These are the answers we give in writing.

What is exposed to the internet?

One hardened gate on port 443. Apps answer on the Pilae private mesh, and machines have closed ports and key-only SSH.

Who can reach our environment?

Named Pilae engineers with personal accounts and only the rights their task needs. No shared logins. The access list is available on request.

How fast are vulnerabilities fixed?

Upstream advisories are matched against the versions you run. A fix is planned with a backup and a rollback, and sent for approval as soon as it is published.

What is the record?

Every login, approval, command and configuration change is kept in the console and exportable to your SIEM.

Where do logs go?

Application logs stay on the machines that produced them. The console reads them on demand and does not copy them to a central store.

Who responds to an incident?

Pilae engineers, alerted by probes every 60 seconds. Enterprise adds around-the-clock incident response with a named engineer.

A smaller attack surface, and a record of every change

A SaaS estate spreads your data across vendors whose controls you read about in a report once a year. A self-hosted estate brings it back, but only helps if it is run with discipline: patched on time, reachable by few people, and recorded.

Pilae runs every deployment on the same model. Apps answer only on a private network, behind one hardened gate on port 443. Our engineers have named accounts with least privilege. The Pilae Agent plans every change with a backup and a rollback, and nothing applies without an approval. The full security model is published, and networks with no internet connection are covered by air-gapped deployment on Enterprise.

Security tools in your own estate

Some of the apps we operate are security tools in their own right, run for your teams on the same terms as any other app: a pinned version, daily backups, fixes applied in your window. Wazuh collects and correlates events from your servers and endpoints if you have no SIEM yet. OpenBao keeps application secrets and certificates out of configuration files. NetBird gives your own staff access to internal systems by identity and group, instead of a VPN that opens the whole network. Passbolt and Vaultwarden hold shared passwords, and Harbor scans the container images your developers build before they run.

Who is responsible for what

Security is shared between your organisation, Pilae and, in Pilae Cloud, the datacentre operator. The shared responsibility page sets out who owns each layer, from physical security to user accounts, so your risk register can name an owner for each control.

Evidence your auditors can use

Every plan, approval, command and result goes to the audit trail, which you can export to your SIEM. Restore tests are recorded every month, as described on the backups page. If a regulator asks how a change was made, the answer is already written down. For regulated sectors, see NIS2 and DORA and FINMA outsourcing, and for what Pilae and its providers hold, the certifications page.

Vulnerabilities in the platform can be reported to security@pilae.com, as described in our disclosure policy.

How a security review with Pilae runs

  1. Questionnaire

    Send your security questionnaire. We answer it before you sign, with the evidence behind each control.

  2. Architecture walkthrough

    An engineer takes your team through the network, access model, backups and change process for your deployment.

  3. Your own tests

    Run your own penetration test against your deployment, by arrangement. Findings are planned and fixed through the same approval process as any change.

  4. Ongoing evidence

    The audit trail flows to your SIEM, restore tests are recorded monthly, and changes are reviewable in the console at any time.

What you get in writing

Security measures
Technical and organisational measures in an annex to the DPA, built to ISO 27001 controls.
Audit rights
Included on every plan, with access to the audit trail for your auditors.
Incident notification
Any security incident affecting your data is reported without undue delay, as your data processing agreement specifies.
Security fixes
Critical fixes planned and sent for approval as soon as the upstream fix is released. Response times per plan.
Audit trail
Retained for the length of the contract, exportable to your SIEM and handed over at exit.

The apps behind it

Keycloak

Single sign-on for everything else you run, with your own directory as the source of truth and no per-seat bill between you and it.

Replaces Okta, Microsoft Entra ID

Wazuh

Security monitoring with an agent on every server and workstation: logs, file changes, vulnerabilities and configuration checks, analysed and kept in Switzerland, the EU or your own datacentre.

Replaces Splunk Enterprise Security, Microsoft Sentinel

OpenBao

Secrets, certificates and encryption keys for your applications, run on your own hardware or in a Pilae region, with the unseal keys held by you rather than by us.

Replaces HashiCorp Vault, HCP Vault Dedicated, AWS Secrets Manager

NetBird

Access to internal systems over WireGuard, granted by the groups in your directory, with the control plane run in Switzerland, the EU or your own datacentre.

Replaces Tailscale, Zscaler Private Access, Cisco AnyConnect

Passbolt

A team password manager built on OpenPGP, where every shared credential is encrypted for each person who may read it, run in Switzerland, the EU or your own datacentre.

Replaces 1Password Business, LastPass, Keeper

Vaultwarden

A password manager for the whole organisation, compatible with the Bitwarden apps, on a server you choose and with vaults only your people can decrypt.

Replaces 1Password, LastPass

Harbor

A private container registry that scans and replicates your images and caches Docker Hub, run in Switzerland, the EU or your own datacentre.

Replaces Docker Hub, Amazon ECR, Azure Container Registry

Grafana

Dashboards and alerts over your metrics, logs and traces, run in Switzerland, the EU or your own datacentre so the telemetry stays with you.

Replaces Datadog dashboards, New Relic

Nextcloud

Files, calendars and shared documents for the whole organisation, on storage you can point at in a room you control.

Replaces Google Drive, Dropbox, SharePoint

Questions

Is Pilae ISO 27001 certified?

Pilae operates to ISO 27001 controls and describes them in the security annex to the DPA. In Pilae Cloud, machines run in ISO 27001-certified datacentres. The certifications page sets out what each party holds.

Can we keep everything inside our perimeter?

Yes. On premises, the apps, the Pilae Agent and the logs run on your servers. Enterprise covers air-gapped deployments, where Pilae signs each release and hands it over through the transfer process your security team defines.

Can the Pilae Agent act on its own?

No. By default every change waits for a person to approve it. Rules that approve routine changes are yours to write, and every action is recorded either way.

Which AI model does the agent use, and does it send data out?

The planning model is configurable. You can run it on a model hosted inside your own perimeter, so no prompt or log line leaves it. An external model is used only if you enable it.

Does Pilae help with NIS2 and DORA?

Pilae gives you the controls, contract terms and records those frameworks ask of an ICT provider: incident notification, audit rights, an exit plan and an exportable audit trail. Whether and how they apply to your organisation is for you and your advisers to decide.

Related

Send us your questionnaire.

We answer it with the evidence behind each control, and an engineer walks your team through the architecture of your deployment.