EdgeKeeper security

Sees everything. Touches nothing. Leaves nothing behind.

Switchboard plugs into the systems that run your business — PSA, RMM, client tenants, billing. We built it assuming it will be attacked through the data it reads: a ticket note, a device name, an uploaded PDF. So the engine runs read-only, inside a sandbox that is thrown away after every turn, on a network that reaches only the hosts we name.

Standard v1.4 · 2026-09-20

In plain terms

Where does my data live?

In a database we run, and on an EdgeKeeper Server in our own cloud tenant that has no public address. The server can only be reached through one hardened jump host, from our controller, over a key. Your data and everything the engine learns about your business are yours, with full export rights in the contract.

Can it change anything in my systems?

Not on its own. Every turn is narrowed to read-only before it starts, on every plan — the engine is never holding a token that could change something. A change happens only after a person approves one specific call, and that approval is good for exactly one call of one tool.

What does the AI actually see?

Only what the person asking is allowed to see, and only what a named question asks for. We never bulk-ship your data to a model: it asks through tools, one call at a time, and every call is written down for you to read. Credentials are never part of the conversation.

Who can see what?

You grant people data domains — service, finance, sales, company, assets, projects, people — and the database enforces them. A technician without finance gets an empty value where billed hours would be, and so does the engine when it answers for that technician.

What if someone tries to trick it?

We assume they will, through the data it reads — a ticket note, a device name, a file. Every piece of text that comes from your systems is wrapped and labelled as data rather than instructions before the engine sees it, and the engine's standing rule is that only you can authorise an action.

What happens if a server is attacked?

Each turn already runs in a throwaway sandbox with no route to the internet except one allow-list door, so there is nowhere for stolen data to go. The host itself is held to a published standard of checks, and a server that fails one is not allowed to run. The record of what happened leaves the machine every ten minutes to somewhere the machine cannot reach.

What about HIPAA and SOC 2?

We hold no external audit report and no certification, and we say so rather than implying otherwise. What we have is a published standard of controls, each with the check that proves it. For regulated work the condition is explicit: we deploy on the API tier under a zero-retention agreement, and the paperwork is signed before any patient data moves.

What happens to our data if we stop working together?

You leave with it. The records, everything the brain learned about how your business runs, and the log are yours, with full export rights in the contract from the first day. Leaving is a documented handover, not a negotiation. The server and the software stay ours to run.

Ask the person who built it

Your security questions deserve a direct answer.

Talk with Brian Kelly about EdgeKeeper, your infrastructure, and how it fits your MSP. He’ll explain it himself.

Ask Brian about EdgeKeeper