Your data never leaves your cloud. Your keys never leave your KMS.
Yeti deploys inside your own cloud account. Telemetry is compressed at the edge, written to your bucket, and encrypted with keys you control. The control plane operates the software and has no path to your data.
Everything that touches your data runs inside your account.
The line is drawn so that the product runs where the data already lives. The control plane coordinates the deployment. It never sees a log line.
Four controls, and every one of them is yours to hold.
Cloud-native identity, no shared secret
The agent assumes a short-lived, scoped role in your account: IAM Roles for Service Accounts on AWS, Workload Identity on GCP, Managed Identity on Azure. The vendor never holds a long-lived credential to your data.
Your keys, generated and revoked by you
Every chunk is encrypted at rest with a key you create and rotate in your own KMS. Revoke it and the archive goes dark on your command, with no support ticket and no vendor in the loop.
Encrypted end to end
Data is encrypted at rest with your KMS key and in transit with TLS. The bytes are protected from the edge where they are collected to the bucket where they come to rest.
Air-gap option
For classified and sovereign estates, the deployment runs with zero outbound to the control plane. Detection, retrieval, and the agent all run against data that never leaves the enclave.
Built for the buyers who cannot move their data.
Financial services, healthcare, defense, and critical infrastructure increasingly mandate that a security vendor runs where the data already lives. The cleanest tenant boundary an auditor accepts is your own cloud account.
Keep every security signal. Keep it in your cloud.
Tell us what your environment looks like and we will map the deployment to your cloud, your keys, and your residency requirements.
