Sign-in and accounts
- Passwords are never stored in plain text, but as scrypt hashes with a unique salt per user.
- Two-factor authentication (TOTP) is available to every user, with single-use recovery codes stored as hashes.
- Sign-in, the two-factor step, sign-up and password reset are rate-limited against repeated attempts.
- Sign-up does not reveal whether an email address already has an account.
- Sessions are stored on the server. The cookie is
HttpOnly,SecureandSameSite=Lax, and sessions expire after 14 days of inactivity. - Failed sign-ins are recorded in the organisation's audit log.
Access and isolation
- Each organisation is logically isolated. Every database query is scoped to the user's own organisation.
- Roles (owner, administrator, editor, read-only) control who can change what.
- API keys have limited scope (read, write or agent reports only), are shown only once, are stored only as hashes and can be revoked. Last use is shown with time and IP.
Traceability
Every change to addresses, subnets, ranges, users and API keys, as well as sign-ins, is written to an audit log with user, time, IP address and old and new value. The log is protected against modification in the database: existing entries cannot be updated.
Snapshots
Every organisation has snapshots of its whole IP inventory: automatic every day something has changed (kept for 30 days), automatic before every import and restore (kept for 90 days), and manual named snapshots (up to 20). Only administrators can restore. Before a restore you see what will be added, removed and changed, a new snapshot is taken first, and every changed address is recorded in the audit log.
Snapshots are stored in the service's database, per organisation. They protect against mistakes in the data – such as a bad import – but are not an off-site backup of the platform. Consider downloading important snapshots as Excel or JSON.
Transport and storage
- All traffic uses HTTPS with HSTS.
- The service and database run on servers in Norway.
- The database is backed up regularly.
- We use no analytics tools, tracking cookies or ad networks.
Agents and collector
- The agents and collector connect out to ipmanager over HTTPS. You do not need to open any inbound ports to your network.
- The scripts are plain text with no binaries, so you can read what they do before running them.
- Agent keys can only send reports. A leaked agent key gives no access to read your data.
Your responsibility
- Enable two-factor authentication, and require it for everyone with administrator access.
- Remove users who leave, and revoke API keys that are not in use.
- Keep API keys in files with restricted access.
Reporting vulnerabilities
Found a possible security issue? Send a description via the contact form (choose “Security”). We will respond as quickly as we can and ask that you do not publish the issue before it is fixed. Do not test against other customers' data, and do not carry out denial-of-service attacks.
See also the privacy policy and the terms.