Security by design

Monitoring should reduce uncertainty, not create new risk.

Hosen Cyber is being built around a constrained external-assurance model: verify the asset, minimise active probing, isolate customer access and preserve the evidence needed to explain what happened.

Verified domain ownership

A customer must prove control of a domain before that asset is assigned to its account for monitoring.

Explicit active-scan authorisation

Active exposed-port assessment is gated separately from domain verification and is not run against arbitrary customer-entered domains.

Authenticated customer access

Customer-facing monitoring data is returned only through authenticated application flows with tenant-aware access checks.

Tenant-scoped data

Customer domains, alerts and dashboard access are associated with the customer account rather than exposed through a shared global view.

Durable change history

Monitoring results and significant status changes are persisted so current posture can be understood in context rather than as a one-off scan.

Tracked notification delivery

Alert delivery has its own state, allowing Hosen Cyber to distinguish a security finding from a failed or successful email notification.

Scope

External assurance, deliberately bounded.

Most Hosen Cyber controls rely on publicly observable internet-facing information and do not require access to a customer's internal network, endpoints or business systems.

Where a control involves active probing, the product requires additional authorisation. The service is not intended to replace penetration testing, managed detection and response, internal vulnerability management or formal certification.

That separation is intentional: Hosen Cyber is designed to provide continuous evidence between deeper assurance activities, not to claim coverage it does not provide.

Questions about how Hosen Cyber handles monitoring or customer data?