Skip to content

leaksignal/leaksignal

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

LeakSignal Tweet

Mesh Native Runtime Security 🎉

License

🔍 How can I observe and secure sensitive data travelling across the Service Mesh data plane without impacting performance? 🤷

📙 Documentation

LeakSignal installation and reference documents are available at leaksignal.com.

👉 Quick Start

👉 Installation

👉 Sample Policies

LeakSignal provides observability metrics and redaction capabilities for sensitive data contained within service mesh protocols. LeakSignal metrics can be consumed by Prometheus, pushed as OpenTelemetry, or collected in a centralized dashboard - giving MeshSecOps engineers (Incident Repsponse, SRE, DevOps, Platform Eng., SOC etc) a new security tool to help combat API exploits, unknown misconfigurations and sensitive data leakage.

Features

  • Fast, inline Layer 7 request/response analysis.
  • Easy to configure rules ("L7 policy") for detecting and analyzing sensitive data (e.g. PII) leakage.
    • Detect PII, part numbers, account numbers, patient info, grades, dates, email addresses, large arrays, etc. You can write your own matcher or use our constantly evolving ruleset library (contributions welcome).
  • Cloud dashboard with policy editor, monitoring, and alerting.
  • Analysis metrics can be exposed via Envoy and thus reflected wherever Envoy metrics are configured to land (OpenTelemetry, Prometheus, etc.)

Commercial support

License

Copyright 2023 LeakSignal, Inc.

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.