The boundary
Everything sits inside your boundary. We sit outside it.
The app, its database, its secrets and its sign-in all run in your environment, behind your network and your logging. Longhorn the company has no access and keeps no copy of anything your people say.
Your cloud or data centre
Your network · Your logging
For your security team
Built to pass your review, not to ask for exceptions.
Each point says how it is assured, so your architect knows what to check.
Your data stays with you
Interviews, maps and findings live in a database inside your environment. Longhorn holds no copy.
By designPrivate by default
The database has no public address. Access to the app can be limited to your internal network or placed behind your own identity proxy.
ConfiguredAccounts you control
Your administrators create every account. There is no self-sign-up, and sign-in is protected against repeated guessing.
Built and testedSecrets in your vault
Credentials are held in your secret manager and read only by the services that need them.
BuiltPeople, not surveillance
No screen recording, no analytics, no telemetry. Colleagues are described by role, and email addresses never appear in what gets shared.
Built and testedYou set retention
Records are deleted automatically after a period you choose. Anyone interviewed can ask for their record to be removed.
BuiltHard to lose
Deletion protection, daily backups and infrastructure defined as code, so an environment can be rebuilt the same way every time.
ConfiguredSafe on the web
A strict content security policy with no third-party hosts. Errors return a sentence, never internal detail.
Security reviewedTested on every change
A full automated test suite, including every security fix, runs before any new version is released.
Built and testedHow a deployment runs
Your review comes first. Your change process applies.
- Step 1 · Review
Your security architect reviews the architecture and data flow before anything is installed.
- Step 2 · Fit
We map the deployment to your standards: network, identity, logging, keys and retention.
- Step 3 · Pilot
Your platform team, or we under your supervision, deploy to a non-production environment and run the pilot there.
- Step 4 · Production
Production follows on the same code. New versions arrive when you choose to deploy them, through your own pipeline.
For security teams
Everything your architect needs, in one pack.
Architecture, data flow and a walkthrough of how Longhorn is deployed, ready for your review.