Security & Trust

You're installing an agent inside your network. Here's exactly what it does — and what it never does.

Bayqus watches your servers, PCs and network gear from the inside, so a lightweight agent runs behind your firewall. That's a fair thing to scrutinise. This page lays out — in plain terms — how the agent connects, what it collects, what it can't touch, and where your data lives.

Outbound-only, no inbound port Encrypted TLS in transit Health metrics only — no activity tracking
01 — The connection

The agent reaches out. Nothing reaches in.

The agent opens a single outbound TLS connection (MQTT over port 8884) to the Bayqus core. Your firewall already allows outbound connections, so nothing has to change — and because the traffic is outbound, no inbound port is ever opened on your side, and there is no VPN.

Your site — behind NAT / firewall

Bayqus agent

  • Runs on one host per site
  • Collects local health metrics
  • Polls agentless gear over SNMP
outbound TLS
MQTT · port 8884
Bayqus core

Ingest & dashboard

  • Receives pushed metrics
  • Stores history & fires alerts
  • Serves your dashboard
Zero inbound exposure. Poll-based tools (like classic UptimeRobot or PRTG probing from outside) need an open port or port-forward to see a device behind NAT — a permanent hole in your perimeter. Bayqus never asks for one.
02 — What the agent collects

Health and telemetry. That's the whole list.

Everything the agent reports is operational health data — the kind of signal you'd read off a status page. No documents, no messages, no user behaviour.

System health

  • Online / offline state
  • CPU & RAM usage
  • Disk usage per volume
  • Uptime
  • Network in / out
  • Disk I/O & SMART health

Services

  • Critical service up / down
  • Whether a named process is running

Inventory

  • Operating system
  • Hostname
  • IP address
  • Active username (who is logged in)

Optional posture opt-in

  • Antivirus present / active
  • Pending OS updates

SNMP device facts

  • Reachability (switch / printer / UPS)
  • Port up / down & traffic
  • Printer toner / paper level
  • UPS battery & load

What the agent never does

This is the line we don't cross. The agent has no capability to observe or control what people do on their machines. It is a monitoring sensor, not surveillance and not remote access.

  • No keystroke loggingIt never records what anyone types.
  • No screen captureNo screenshots, no screen recording.
  • No file access or exfiltrationIt doesn't read, copy or upload your files.
  • No productivity or activity trackingNo app usage, no idle-time scoring, no timesheets.
  • No remote control of user sessionsIt can't take over a desktop or move a mouse.
03 — How your data is protected

In transit, at rest, and who can reach it.

In transit
Every agent-to-core connection is encrypted with TLS 1.2+ (MQTT over port 8884). Metrics are never sent in the clear.
At rest
Metrics are stored on access-restricted infrastructure in the EU and Azerbaijan.
Access control
Each device authenticates with its own per-device enrollment token, and access is scoped so an agent can only publish under its own device. Dashboard access is restricted to your team.
Where it's stored
On the Bayqus core, in an access-restricted database running on self-managed infrastructure in the European Union and Azerbaijan.
Retention
Metric history is retained on a plan-driven schedule — your plan sets how far back history is kept, then older data ages out automatically.
04 — Ownership & residency

It's your data. And you can keep it entirely on your own ground.

You own your data

The monitoring data we collect on your behalf is yours. We process it to run the service you asked for — nothing more.

On-prem option — full sovereignty

Need the data to never leave your walls? Run the Bayqus core on your own infrastructure. The agents push to your server, and no monitoring data reaches us at all.

  • Your infra, your network, your retention.
  • Talk to us about an on-prem setup.
05 — Integrity & disclosure

You stay in control of the agent — and of telling us if something's wrong.

Agent integrity

  • Predictable, inspectable behaviour — it does exactly what's listed above and nothing else.
  • Scoped per-device token — an agent can't impersonate another device.
  • Updates are delivered over the same authenticated outbound channel the agent already uses.
  • Uninstall anytime — remove the agent and reporting stops immediately.

Responsible disclosure

Found a security issue? We want to hear it before anyone else does. Report it privately and we'll work with you on a fix.

Go deeper

Configure the agent, or monitor devices it can't reach

The fine print

The documents behind the promises

Have a security question? Talk to us.

Send it to your security or compliance team first — then send it to us. We'd rather answer the hard questions up front than after you've signed.

Talk to us Email security