Support  /  Security model

Security model

SquidGrid is built so that putting a probe inside your network asks very little of you and gives away nothing about your traffic. Here is exactly what runs, what it can reach, and what we can and cannot see.

The probe is unprivileged and outbound-only

A probe is a single container. It runs unprivileged and non-root, with Linux capabilities dropped. It opens no inbound ports and listens for nothing — there is no surface to reach it on. All of its connectivity is outbound: HTTPS (TCP 443) to deliver readings, ICMP echo for reachability and latency measurement, and UDP with returned ICMP for traceroute. Nothing initiates a connection to the probe, ever.

PropertyWhat it means for you
No inbound portsNothing to firewall, nothing exposed, nothing to attack from outside.
Unprivileged, cap-dropNo root, no elevated host access.
Outbound onlyHTTPS (TCP 443) to deliver readings, ICMP and UDP to take measurements. Nothing connects in.
Delete to removeStop and delete the container and it is gone — no agent left behind.

We measure paths, not your traffic

This is the important one. A probe performs active measurement — it sends its own timed probe packets along a route and records how they behave: round-trip time, loss, jitter, and the sequence of hops. It does not capture, inspect, decode or store your traffic. There is no packet capture of your users' data, no payload inspection, no mirror of your network.

What we learn is how the road behaves, not what is driving on it. We can tell you the path to your payment provider slowed and where it began — not who paid what.

A probe measures only the destinations you configure. We never add our own targets to a customer's probe, and we do not measure your internal network unless you point a target at it.

Your data is scoped to your account

Everything a probe reports belongs to your account. When you sign in, you see only your own sites, links and measurements — every request is scoped to your account, and one customer's data is never served to another. Your access to the dashboard is read-only reporting: you view and arrange your measurements; you cannot reach anyone else's, and the global fleet's raw carrier detail stays separate from the public view.

What we hold, and what we don't

Retention, processing and your rights over this data are set out in our privacy policy and data processing agreement.

The probe is open to inspection

You do not have to take our word for any of this. The probe image is public on Docker Hub at squidgrid/probe, and we welcome people taking it apart to confirm exactly what it does and does not do before they run it.

Reporting a vulnerability

If you find a security issue in the probe or the service, please write to [email protected]. We read it, we act on it, and we will work with you on disclosure. Good-faith research is welcome.

Next: How our probes measure  ·  Install a probe  ·  back to all guides