Uplivra
Security

Security first, by design

Monitoring software sees your whole network, so it has to be the most trustworthy thing on it. Here's how Uplivra is built.

Your data stays yours

Uplivra runs on your servers. Monitoring results, logs, flows, configurations and passwords never leave them. The daily license check sends device counts and the version, nothing else.

Strong encryption everywhere

Collectors talk to the server over TLS 1.3 with post-quantum hybrid key exchange (X25519 + ML-KEM-768), pinned to your server's certificate or checked against your own certificate authority. Log archives are encrypted with AES-256-GCM.

Upgradeable cryptography

Encryption profiles are settings, not code. When standards move, a signed update changes the defaults, and you can tighten them yourself today.

Passwords stay on the collector

SNMP communities and device passwords are kept in an encrypted vault on the collector that uses them. The server never receives them.

Signed updates, checked programs

Every release is signed with Uplivra's Ed25519 key and checked before it's installed. The program checks its own integrity and warns if it has been changed.

Tamper-evident logs

Stored logs are hash-chained, so a deleted or edited entry shows. Off-site copies can use S3 Object Lock, so even an administrator can't delete them early.

Hardened appliance

The virtual appliance is Ubuntu LTS hardened to CIS Level 1: root locked, SSH off by default, host firewall closed except what the role needs, AppArmor enforcing, audit logging, automatic security updates.

Sign-in protection

Two-step sign-in, sign-in history, idle sign-out after 5–30 minutes, admin and viewer roles, and an audit log of every change.

Your own certificates

Create a signing request in the web interface or on the command line, upload your certificate, and Uplivra uses it for the web interface and collector relays.

Reporting a vulnerability

Email security@uplivra.com. We reply within two business days and credit researchers who report responsibly. Please don't test against other customers' systems.