Skip to content
Self-hosted or hosted: Compare the two

Security and trust

You hold the keys to your customers. So do we.

An MSP platform can reach every machine and tenant you look after. Here is how Tenvara is built to deserve that access, in plain terms.

The credentials vault with every reveal recorded in an audit trail

Access and sign-in

Two-factor for everyone
Local accounts use TOTP two-factor, and admins can make it mandatory.
Single sign-on
Entra ID, Google Workspace, any OpenID Connect provider, or SAML 2.0, with group to role mapping and domain enforcement.
Break-glass access
Local sign-in stays available to a named admin when single sign-on is required for everyone else.
Roles and permissions
Admin, technician and read-only, with permissions per module and staff access scoped by customer.

Data

Encrypted secrets
Credentials, TOTP seeds, licence keys and integration tokens are encrypted at rest and only decrypted when used or revealed.
Every reveal audited
Revealing a credential records who, what and when. Nothing secret is shown by default.
Encryption in transit
Every connection, from the browser and from the agent, uses TLS.
Your data, your location
Self-hosted installs keep everything on your infrastructure. Hosted instances each have their own database.

The agent

Signed builds
Windows and macOS agents are code signed, and updates are verified before they install.
Self-update with rollback
A failed update rolls back rather than leaving a device unmanaged.
Signed scripts
Scripts run on devices come from your server over the agent connection, not from arbitrary sources.
One connection
Every module talks to the server through the one authenticated agent connection.

AI and third parties

Off by default
AI features do nothing until you add your own Anthropic API key.
Read-only unless approved
The assistant runs read-only checks. Anything that changes a device needs a technician to approve it.
Listed and logged
Settings lists exactly what is sent to the model, and every AI call and result is logged on the ticket.
Per-customer opt-out
Switch AI off for any customer who does not want it.

Reporting a vulnerability

If you think you have found a security problem in Tenvara, email security@tenvara.io with the details and how to reproduce it. We will acknowledge it, keep you updated, and credit you if you would like. Please give us a reasonable time to fix it before telling anyone else, and do not access data that is not yours.

Data protection

For hosted instances we act as your processor under UK GDPR and EU GDPR. Our data processing agreement sets out what we do with the data and how we protect it.

Security questionnaire to fill in?

Send it over. We'll answer it properly rather than pointing you at a badge.