ET Ducky ET Ducky
Home Blog Documentation Pricing Book a Demo Downloads
Blog Documentation Pricing Downloads
Settings
Sign Out

Compliance and security review documentation

Last Updated: September 2, 2026

ET Ducky runs privileged code on endpoints, which means a security review is a reasonable thing to ask for before a deployment. These pages document what the platform's controls do, which regulatory requirements they produce evidence for, and which they do not. Where an attestation does not exist, the page says so rather than describing readiness work as though it were a report.

What ET Ducky holds today

ItemStatus
SOC 2 Type I or Type II reportNot held. Readiness work in progress.
ISO 27001 certificationNot held. Controls mapped to Annex A in the whitepaper.
FedRAMP authorizationNot held. No package in progress.
StateRAMP or GovRAMP authorizationNot held. No package in progress.
VPAT or Section 508 conformance reportNot published.
Published security whitepaper with control mappingAvailable. Read it.
Public security posture and sub-processor listAvailable. Read it.
Public status page with uptime historyAvailable at status.etducky.com.
Written response to a customer security questionnaireAvailable on request.
Sub-processor attestationsCurrent for all six sub-processors.

A control mapping is a self-assessment performed by the vendor. It has not been examined by an independent auditor and is not offered as a substitute for one.

Documentation by framework

Cyber insurance endpoint control questions

The endpoint control questions on an application or a renewal, each answered with the specific mechanism: behavioral detection, automatic isolation and its dual-approval release, command logging, retention tiers, and where data is stored. Written to be forwarded to a broker or an underwriter without editing.

HIPAA Security Rule endpoint controls

Which Security Rule citations an endpoint agent produces evidence for, principally 164.312(b) audit controls and 164.308(a)(1)(ii)(D) activity review, plus the narrow route by which an identifier could enter telemetry and the business associate question that follows from it.

SOC 2 endpoint logging controls

The full control mapping to Trust Services Criteria CC6 and CC7, the records available as evidence in a customer's own audit, and the attestation status stated first rather than last.

GLBA Safeguards and FFIEC endpoint monitoring

Which regime applies to which institution, since banks and credit unions answer to different citations than non-bank financial institutions for the same control, then the endpoint requirements themselves: 314.4(c)(8) logging, (c)(5) multi-factor authentication, (c)(3) encryption, (c)(6) disposal and the (d) monitoring alternatives.

Public sector procurement facts

Authorization status first because several requirements are disqualifying, then hosting and United States data residency, sub-processors, the self-hosted deployment for agencies that cannot place telemetry with a cloud vendor, and contracting facts.

Where the platform fits in a control program

An endpoint monitoring agent produces evidence for a specific band of requirements and nothing outside it. The band is roughly: logging of privileged user activity, detection of unauthorized or anomalous behavior, containment of a compromised endpoint, endpoint configuration posture, patch state, and encryption of the data the platform itself holds.

It supplies nothing for risk assessment, workforce training, policy, physical safeguards, contingency planning, board reporting or vendor contracting. Those are program obligations, and any vendor page suggesting otherwise is selling.

The one structural claim worth making is about where evaluation happens. Behavioral rules are evaluated against events already streaming from the kernel, through Event Tracing for Windows on Windows and eBPF on Linux, rather than against a report from the process being evaluated. For a reviewer asking how unauthorized activity would actually be noticed, that is the substance of the answer.

Deployment options that change a review

Two facts often resolve a review that would otherwise stall.

Self-hosted. The Local-First tier runs the same server codebase on customer infrastructure. Cloud-only surfaces are removed from the application model at startup rather than blocked, no vendor-side secrets ship, and endpoint telemetry lands only in the customer's own PostgreSQL. For an organization whose vendor policy requires an attested provider, this moves the data out of scope for that policy.

Bring your own AI key. AI analysis is user-initiated rather than automatic, and it is the only path by which data leaves United States infrastructure. It can be disabled, or run against the customer's own provider key.

Have a questionnaire, a control list, or a solicitation?

Send it. What comes back is a written answer mapped to the citations your reviewer uses, with the items ET Ducky does not satisfy named rather than omitted. That is faster than reading five pages, and it is the document your file actually needs.

Book a 25-minute review call Request the questionnaire response

Questions about a specific control go to [email protected]. The security whitepaper is the source of record for everything on this page.

ET Ducky

AI-powered kernel-level diagnostics for Windows and Linux

Product

Documentation Pricing Downloads

Support

Documentation System Status Contact

Security

Security Posture Security Whitepaper Compliance Security Documentation

Legal

Privacy Policy Terms of Service EULA

© 2026 ET Ducky. All rights reserved.

Contact Us

Email
[email protected]
Phone
+1-817-880-1336