Security architecture

Security at Troubleshoot AI

A constrained operational architecture built around outbound communication, strong identity, organization-scoped authorization, and controlled diagnostics.

Outbound-first architecture

The Client initiates communication with the platform. Normal monitoring does not require an inbound cloud connection.

Encryption in transit

Client and browser communication uses HTTPS/TLS.

Authentication and MFA

Google and Microsoft OAuth are supported with TOTP MFA and stronger authentication for privileged administration.

Organization-scoped authorization

Account membership and resource ownership are enforced server-side for inspected operational endpoints.

Controlled Remote Logs

Diagnostic logs are requested through defined workflows, redacted before upload, bounded in size, and expired after their visibility window.

Constrained product direction

No AI diagnosis or remediation shell exists today. Future automation is designed around policy-approved actions rather than unrestricted shell access.