Product boundary

Governance evidence, not a second inventory or SIEM.

Control9 records structured outcomes from signed, redacted pipeline requests. This marketing site does not store tenant evidence or require SaaS credentials to browse.

Accounts and access

Browsing this marketing site does not require Control9 credentials. Team accounts in the admin app use work email or Google. Colleagues join through admin invite (any verified email) or same-domain auto-join when your organization allows it. GitHub is used to install and run the Control9 Action in CI; it is not an admin login method.

Captured by default

  • Evidence metadata and timestamps
  • Plan and template fingerprints
  • Policy context and decisions
  • Approval and execution records
  • Redacted excerpts that explain outcomes

Not captured by default

  • Raw secrets, tokens, and private keys
  • Full source code and full command output
  • Complete Terraform state or raw templates by default
  • Detailed cloud inventory beyond governed events

How evidence is handled

Redaction

GitHub Actions and GitLab send signed, redacted envelopes. Reviewers see summaries and fingerprints, not raw secrets or unredacted logs by default.

Export and storage

Customer-owned export and storage are tenant capabilities tied to package entitlement. This public site is not your evidence system of record.

Retention

Free 30d, Team 90d, Growth 180d. Enterprise and Managed Controls can negotiate longer windows. See pricing for package limits.

Enterprise and later

Customer-hosted or hybrid control plane

Customer-owned storage and SIEM export

SSO/RBAC, private networking, data residency

Managed Controls advisory

These are package, enterprise, or roadmap paths. Public copy does not claim they ship in every self-service tenant.

Next step

Start with a shadow-mode assessment or contact path. Do not submit secrets, tokens, private keys, IaC artifacts, or detailed inventory through public email or forms.