Security & Data Protection
Your Infrastructure. Your Data. Your Control.
Bitanix NetMan is built for IT professionals who work with sensitive network and infrastructure information.
Security and data protection are integrated into the way NetMan stores projects, handles credentials, establishes remote connections, performs network assessments, and uses external AI services.
Our approach is based on a simple principle:
Your infrastructure data should remain under your control.
Local-First by Design
Bitanix NetMan follows a local-first architecture.
Your projects, network topology, device inventory, documentation, and other operational data remain on your local system by default.
NetMan does not require cloud storage for normal project operation, and core functionality does not depend on mandatory telemetry.
Network and project information is not automatically uploaded to BitanixSoft.
This allows organizations and IT professionals to maintain direct control over where their infrastructure data is stored.
Protected Project Files
Projects may contain sensitive information about network architecture, devices, addressing, infrastructure, and security posture.
For environments requiring additional protection, NetMan supports password-protected projects using authenticated encryption.
Protected projects use AES-256-GCM encryption to help preserve both the confidentiality and integrity of project data.
The application is designed to reject incorrect passwords, modified encrypted data, and corrupted protected projects rather than falling back to an insecure plaintext mode.
Temporary working data associated with protected projects is also managed within a controlled workspace and cleaned up after use.
Secure Credential Handling
Credentials require a different level of protection from ordinary project information.
Where practical, NetMan keeps reusable secrets outside project files.
This includes supported credentials such as:
-
SSH passwords
-
SSH private-key passphrases
-
SNMP credentials
-
API keys
-
Other supported authentication secrets
Sensitive values are stored using the operating system's supported secure credential storage.
NetMan does not silently fall back to storing these secrets as plaintext when secure credential storage is unavailable.
This helps reduce the risk of sensitive authentication information being exposed through copied, shared, or backed-up project files.
SSH Host Protection
Remote infrastructure management requires confidence that you are connecting to the intended system.
NetMan uses explicit SSH host verification.
When connecting to a previously unknown SSH endpoint, the host identity requires user approval before it becomes trusted.
Approved host fingerprints can be remembered locally. If the identity of a trusted endpoint changes unexpectedly, NetMan blocks the changed host key rather than silently accepting it.
This provides an additional layer of protection against unexpected endpoint changes and potential man-in-the-middle scenarios.
AI With Your Permission
AI-assisted analysis in NetMan is designed to remain under user control.
Project information is not silently sent to an external AI provider.
Before external AI analysis occurs, NetMan allows you to review the prepared information and requires explicit approval before transmission.
Additional safeguards include:
-
Credential data is structurally excluded where possible.
-
Sensitive information is redacted by default.
-
Unnecessary configuration content is excluded by default.
-
Disabling redaction requires additional confirmation.
-
Cancelling the confirmation prevents the AI request from being sent.
AI-generated recommendations are advisory.
AI output cannot independently execute SSH commands, modify network devices, initiate SNMP operations, or automatically apply remediation actions.
You remain in control of both data sharing and operational changes.
Security-Aware Network Assessment
NetMan includes defensive tools designed to help authorized IT professionals understand the security posture of their infrastructure.
Depending on the feature being used, NetMan can assist with areas such as:
-
Port and service discovery
-
TLS and SSH security assessment
-
Firmware and vulnerability intelligence
-
CVE-related analysis
-
Security finding management
-
Infrastructure risk visualization
-
Security checklist assessments
NetMan is designed to distinguish between identified evidence, lower-risk observations, and systems where sufficient assessment data is not yet available.
A system with no currently identified finding is not automatically presented as proof of security.
These capabilities are intended to support professional security decision-making and infrastructure management. They are not represented as a replacement for authorized penetration testing, independent compliance audits, vendor security advisories, or professional security review.
Controlled Ubuntu Security Remediation
For supported Ubuntu security checks, NetMan separates assessment from remediation.
Identifying a security issue does not automatically authorize NetMan to modify the server.
Supported remediation actions follow a controlled workflow that can include:
-
Identifying the specific finding
-
Preparing the supported remediation action
-
Previewing the proposed change
-
Requiring explicit authorization
-
Creating a backup where applicable
-
Applying the approved change
-
Verifying the result
-
Rolling back when verification or connectivity fails
-
Recording the outcome
Additional confirmation is required for certain operations that may affect services or connectivity.
The objective is to provide useful administrative assistance while keeping infrastructure changes under the control of the administrator.
Security-Conscious Reporting and Export
Network documentation and security reports can contain commercially sensitive infrastructure information.
NetMan is designed to reduce unnecessary exposure when generating security-related reports and exports.
Sensitive credentials are excluded from supported reports by design where applicable, and security-sensitive export workflows include sanitization and controlled handling of temporary data.
Because infrastructure documentation itself can be sensitive even when it contains no passwords, users should always review exported material before sharing it outside their organization.
Privacy by Design
NetMan is designed so that normal use does not require surrendering control of your infrastructure data.
By default:
-
Project information remains on your local system.
-
Network topology and device data are not automatically transmitted to BitanixSoft.
-
Core operation does not require mandatory telemetry.
-
Credentials are kept outside project files where practical.
-
External AI transmission requires explicit user approval.
-
Network operations occur only when initiated by the user.
-
Licensing is verified locally using cryptographically signed entitlements.
-
Password-protected projects use authenticated encryption.
Security Is an Ongoing Commitment
Security is treated as part of the product lifecycle, not simply as a feature.
Bitanix NetMan has undergone structured security hardening and validation covering areas such as:
-
Project data protection
-
Credential handling
-
Licensing security
-
SSH host trust
-
AI privacy controls
-
Network assessment safety
-
Security reporting
-
Dependency and software integrity
-
Installer security
-
Regression and security testing
We also recognize an important reality:
No client-side software or automated security tool can guarantee absolute security.
NetMan is designed to provide strong, practical safeguards while keeping critical decisions and infrastructure control in the hands of the user.
Built for Professionals Who Need Control
Bitanix NetMan is designed for network administrators, IT professionals, consultants, and infrastructure teams who need powerful management capabilities without unnecessarily moving sensitive operational data outside their environment.
Discover. Document. Secure. Manage.
And keep control of your infrastructure.
Privacy Policy
This page describes security and data-protection capabilities built into Bitanix NetMan.
For information about how BitanixSoft handles personal information, website data, account information, purchases, support communications, and other personal data, please review our Privacy Policy.
