SubscribeGo ProYour plan Settings
By industry · Small IT and security teams

OBSCURA for small IT and security teams

A small team does a security department’s work without the budget for its platforms. The Sovereign Suite puts several of those jobs on one machine: SOC 2 readiness, finding sensitive data, a certificate inventory, release signing, folder watch and incident playbooks. Nothing is uploaded, so there is no new vendor holding your data to put through review.

The jobs, and what does each one

The Sovereign Suite is Pro as a whole; its services are marked Pro. Names in capitals are single tools: free to open and to check a file with, and Pro to save the result.

Getting ready for an audit

Most of SOC 2 readiness is knowing which criterion needs which evidence, who owns it and how far it has got.

  • Get ready for SOC 2Pro: every criterion an audit tests, in plain words, with the evidence auditors usually ask for, an owner and a status for each, and a readiness report to export
  • RISK: a five by five assessment that keeps every earlier version and flags a high residual with nobody’s name on it
  • ROPA: the Article 30 record of processing activities
  • RETENTION: a retention schedule, and what is already past its date

The SOC 2 service gets a team ready; it certifies nothing. A SOC 2 report comes only from an examination by a licensed CPA firm.

Knowing what is where

Before a share is migrated, a drive handed back or an export sent, somebody should know what is in it.

  • Find sensitive dataPro: reads every file in a folder and lists the credentials, card numbers that pass Luhn, IBANs, US Social Security and Canadian Social Insurance numbers, and contact details in each, with a report that shows no value unmasked
  • SENTINEL: the scanner behind it, for pasted text, config files and Office documents
  • ENVSHIELD: masks keys, tokens and passwords in a .env, YAML, JSON or log before it goes in a ticket
  • INTERCEPT: strips cookies, bearer tokens and keys out of a .har file or a curl command

Certificates and keys

Certificates expire on a date everybody knew and nobody watched.

  • Certificate inventoryPro: every certificate in a folder, soonest to expire first, with weak keys, forgeable signatures, over-long lifetimes and private keys stored beside them flagged, and a calendar of reminders 30 days before each expiry
  • CERTLENS: takes one certificate or a chain apart and checks it
  • KEYPRINT: SSH key fingerprints as ssh-keygen prints them, and weak or duplicate keys in authorized_keys
  • JOT: decodes a JWT and checks its signature, without sending the token anywhere

The inventory reads what is in the files. It does not ask a CA whether a certificate has been revoked, because that means contacting one.

Proving what you ship and what you hold

A download that cannot be checked, and a folder nobody fingerprinted, are both a matter of trust.

  • Sign a releasePro: signs files with an Ed25519 key in minisign’s format, checked before they are offered, with a signed SHA256SUMS
  • Watch a folder for changesPro: fingerprints every file in a folder, then shows exactly which were changed, added, removed or moved since
  • SIGIL: checks a minisign signature in any browser, with nothing installed
  • VOUCH: who signed a Windows .exe or .dll, and whether it has changed since

Read first: how to show a file has not been tampered with.

When something has gone wrong

The first hour goes better with a list and a clock than with a search engine.

  • Respond to an incidentPro: playbooks for a bad click, a leaked password, a lost device, a misdirected file and being tracked, each step timed and saved as a record
  • Check a file before opening itPro: the real type, anything that runs, and secrets it leaks
  • SOVEREIGN CONSOLE: one workbench for a file: identify, hash, entropy, hex, strings and indicators, decode, carve, YARA and a sealed evidence manifest
  • INCIDENT: an incident worked through its phases, with the record kept as you go
  • BREACH: the reporting clock and the notification when personal data is involved

The playbooks are general guidance for individuals and small teams, and say so; at work, your own incident process comes first.

Mail, logs and the edge

The files a small team is handed most often, read without uploading them to a paste site.

  • DMARC: correct SPF, DKIM and DMARC records and a security.txt
  • MAILBOX: a saved email taken apart: the delivery path, authentication results and where the links go
  • RAMPART: the security headers a server sent, and which are missing or wrong, on staging and intranet pages too
  • SENTRY: an SSH or web access log grouped by source, with brute force and enumeration flagged
  • WIRE: a pcap read in the tab: conversations, DNS and TLS names, and credentials sent in the clear
  • SWEEP: an Nmap scan read, and two scans compared

Read first: reading a pcap without Wireshark and checking who an email is really from.

Secrets that must not be lost

Root keys, recovery codes and the file that needs two people to open it.

Why it matters that the file stays on the machine

A data discovery tool that uploads the share it scans makes a new copy of exactly the data it was meant to find. Here the files are read in the browser window, and the Sovereign services say on screen what they keep: for folder watch, names, sizes and fingerprints in that browser, never the files.

It also changes what there is to review. OBSCURA is a web page over HTTPS with nothing to install, no agent and no account. You can confirm the no-upload claim with the network tab and the offline test on the verification page, which also hashes the files you were served. The page for teams answers the rest of a vendor review, including what we do not have: no SOC 2 report of our own, no SSO and no audit logs.

What is kept stays in the browser where the work was done. A SOC 2 tracker, a folder baseline or a certificate inventory lives with the person who made it, not in a shared console, so export what the team needs to keep.

A worked example: a first week of readiness

A two-person IT team is asked to be ready for a SOC 2 audit and to tidy up before it. With the Sovereign Suite open:

  1. Get ready for SOC 2 lists every criterion. Owners are assigned, and the evidence each one needs is noted against it.
  2. Find sensitive data runs over the shared drive and flags a spreadsheet of card numbers and a config file with a database password. Both are dealt with, and the report, which shows no value unmasked, is filed as evidence.
  3. Certificate inventory reads the folder of certificates from the servers and shows one expiring in eleven days and one still signed with SHA-1. The renewal reminders go into the team’s calendar.
  4. Watch a folder for changes takes a baseline of the production configuration folder, to be checked again each week.
  5. The next release is published with Sign a release, and its public key goes on the website.

What it costs a small team

The Sovereign Suite, with every service on this page, is part of Pro. The single tools are free to open and to check a file with, and Pro to save the result.

Free, for everyone
The Workspace: Docs, Sheets, Slides, Notes, Calendar, Tasks, Contacts, Plan, Drive and the PDF editor, at work as well as at home. And every single tool on this page, to open a file and see what it finds, with no account.
Pro, for one person
$15 a month or $144 a year, with 7 days free. Saving the result in every tool outside the Workspace, the whole Sovereign Suite and the Photo Editor.
Team, up to 25 people
$69 a month or $690 a year, with 14 days free. Everything in Pro for up to 25 people on one key for the whole team, a Stripe invoice with your organisation’s name and tax number, and email answered by a person within a working day.
Not included
No admin console, single sign-on, audit log or shared team storage: each person’s work stays on their own machine. The page for teams lists the rest, with the answers a security reviewer will ask for.

From five people, Team costs less than five Pro subscriptions. Checkout is Stripe’s: the card is asked for at the start and not charged until the fourteen days are over, and if you cancel before then nothing is paid.

Questions

Does the SOC 2 service make us compliant?

No. It tracks readiness criterion by criterion and exports a report for the team or the auditor. Only an examination by a licensed CPA firm produces a SOC 2 report, and the service says so on its own screen.

What does Find sensitive data look for?

Credentials, keys, tokens, passwords and connection strings; card numbers that pass the Luhn check and IBANs that pass mod-97; US Social Security and Canadian Social Insurance numbers; email and public IP addresses. It reads text, code, config, Office documents and PDFs with a text layer, up to 25 MB a file. Other national identifiers, and personal data without a fixed shape, are not in that list.

Is there a central console for the team?

For who has access, yes. On Team and Business the seats page gives each person a key of their own, takes it back, and keeps a record of every seat change for an auditor. There is no SSO or SCIM, and each person’s records stay in their own browser: nothing about what anybody does with the tools reaches a server. The page for teams lists what the plans do not include.

Does it work offline?

The Pro code is kept on the device after the first visit, so the Sovereign Suite keeps working with the network off. The single tools keep working once their page has loaded.

Can we check what we are running?

Yes. The verification page hashes the files your browser was served, so your copy can be compared with anybody else’s.

The same tools, for other work

This page describes what the tools do. Nothing on it is a certification, an attestation or a statement that using them meets any control framework.