Skip to content

security · for the team that has to approve it

Your telemetry stays in your network. Four things can call out, and here they are.

Traces, spans, queries, addresses — none of it goes anywhere. Not for licensing, not for updates. Component names leave only in an architecture review, a notification, or a query to your own Loki — each one something an admin sets up.

Once a day Ritele sends one line: a random install id, the version, how many environments, and whether it’s licensed. A licensed install also names the licence it is running under. That is the whole payload. RITELE_USAGE_PING=false stops it. Full disclosure →

Architecture review calls out, and ships switched off. When you turn it on it uses our gateway unless you choose an endpoint — including a model inside your own network, and then nothing it sends leaves.

Health notifications call out only once an admin adds a channel. What a message carries →

The Logs page reads your Loki, once an admin connects it. What it reads →

R-01

Telemetry stays in your network

No trace, span, query or address leaves the install, and nothing calls out for updates, crash reports or licence checks. One call is on by default and carries none of that: the daily ping (R-06), which RITELE_USAGE_PING=false stops. Three more stay off until an admin sets them up: Architecture Review (R-05), a notification channel (R-10), and the Loki the Logs page reads (R-11). Verify it with a packet capture; we encourage that.

R-02

Single-tenant, your infrastructure

Runs as one container you control: the bundled Collector and the app, with embedded storage on local disk, or your own Postgres and ClickHouse for larger estates. It runs as an unprivileged user, not root. Your installation shares nothing with any other customer's. Beyond the ping receiver (R-06), the one hosted service it can use is the Architecture Review gateway, and only once you enable Architecture Review in managed mode.

R-03

Licences verify offline

Ed25519 signature checked against public keys compiled into the binary — two slots, so signing keys rotate without breaking existing installs. Expiry is enforced locally. Air-gapped installs receive the key as text and paste it in.

R-04

A datastore credential only where you put one

Server readings — connections in use, cache memory, replication lag — come from a Collector's receivers. The bundled Collector connects to a datastore only when an operator adds a receiver file for it, and the credential stays in that Collector's environment: Ritele never writes it to its storage or returns it through its API. Run the receiver in a Collector of your own instead, and nothing in this install holds it.

R-05

Architecture review ships switched off

Once enabled it sends to our gateway, authenticated with your licence key, or to an endpoint you configure instead. For air-gapped installs, point it at a model inside your own network, and nothing it sends leaves your network. The daily ping (R-06) and any notification channel an admin adds (R-10) are separate.

R-06

One line a day, documented

A random install id, the version, environment count, licensed yes/no, and the licence subject where one is applied. Published in full on the disclosure page. RITELE_USAGE_PING=false stops it.

R-07

One signing key, and a record of every licence

Licences are signed with an Ed25519 key held as a secret in the environment of the service that issues them. Every licence it signs is recorded, with the fingerprint of the key that signed it, before the licence is handed over. Releases accept two public keys, so the signing key can be rotated without breaking existing installs.

R-08

Trace data stays put

Only OTLP you route to it is stored, for the retention you set, and nothing is forwarded elsewhere. Metrics count every span. Traces are tail-sampled: every error and every trace you mark for documentation is kept, plus 1% of the rest by default, a rate an admin changes in Settings. If ingest falls behind, kept traces past a 32 MB backlog are dropped and counted rather than held in memory. Everything is stored under the /data volume; deleting the volume deletes the data.

R-09

People sign in, and each has a role

Sign-in is on by default, and each person has one role: viewer, editor or admin. The first start prints a one-time admin password in the container log, which must be changed first; or set it with RITELE_ADMIN_PASSWORD_FILE. A lost password is reset with ritele reset-password <user> inside the container. Every change is logged with who made it. Clearing an environment is off unless you enable it. OTLP on 4317 and 4318 is not authenticated yet. No SSO, multi-factor or API tokens yet.

R-10

Notifications go only where an admin points them

Nothing is sent until an admin adds a channel — a webhook, Slack, Teams or Alertmanager URL, a PagerDuty or Opsgenie key sent to the vendor's host for your region, or an SMTP server — and then only to it, until the channel is removed. A message carries names, the issue's reason with its readings, check statuses, times and a link; never a span attribute, metric label, request URL, header or user identifier. Secrets are sealed (AES-256-GCM) under RITELE_SECRET_KEY, which you set; no channel is saved without it. Only an admin can add a channel; the role comes from the person signed in, and it covers the Health, notification, logs, retention and trace-keep settings. RITELE_ROLE applies only with RITELE_AUTH=off, where it is one role for every caller.

R-11

Logs are read from your Loki, never stored

The Logs page queries a Loki an admin connects, and nothing else. It only reads — labels and line queries, at most 1,000 lines over 24 hours — masks lines as they are read unless an admin turns masking off, and never stores or logs them. Each read is recorded for 90 days. The Loki password or token is sealed under RITELE_SECRET_KEY.

R-12

Known personal-data attributes are removed before anything is stored

The bundled Collector deletes enduser.* and user.* attributes, request and response headers, the url.full and url.query attributes (not the older http.url and http.target, so keep tokens out of URLs), database users and connection strings, and process command lines. Database statements are kept with their values replaced by ?, unless you set RITELE_DB_QUERY_TEXT to raw or off. Log lines are counted by level; their text is never stored.

R-13

Three published ports

The image publishes 4317 and 4318 for OTLP and 8080 for the UI and API. Inside the container, ingest (8081) and the Collector's health, zPages and metrics ports (13133, 55679, 8888) listen on loopback only and are never published. OTLP on 4317 and 4318 is not authenticated, so keep those two ports off networks you do not trust.

R-14

Passwords and sessions

Passwords are hashed with scrypt. Sessions live on the server, which stores only a hash of each id; the cookie is HttpOnly, SameSite=Lax and Secure over https. A session ends after 12 hours idle or 7 days. Failed sign-ins are limited, writes must be JSON and cross-site requests are refused. Behind a platform proxy, set RITELE_TRUST_PROXY to its hop count and RITELE_PUBLIC_URL to your https address; behind a proxy that signs people in for you, RITELE_AUTH=off turns this off.

How a licence is checked

A licence is a signed token (Ed25519). The public key that verifies it is compiled into the binary you download. On start-up and whenever a key is applied, Ritele checks the signature and the expiry date locally. The check makes no network call: there is no licence server and no revocation list to fetch, and therefore nothing to block, proxy, or allow-list. The daily ping (R-06) is separate, and can be switched off.

When a licence expires the install keeps running on the free plan's limits. Your data is untouched.

# what the install knows
public keys      compiled in · 2 slots for rotation
algorithm        EdDSA / Ed25519
claims read      org, sub, plan, features, exp,
                 envs_limit, node_limit,
                 retention_days, hosts_limit,
                 metrics_retention_days,
                 notification_channels_limit,
                 advisor_reviews_per_day
network          none

# what we know about your install
daily ping       install id · version · environments
                 licensed yes/no · licence subject
everything else  nothing
Deployment: one container · Linux x86-64 / arm64 · no sidecars · host metrics need the optional agentData: embedded store under /data · retention you set · delete the volume to delete the dataQuestions for your review: security@ritele.io