Security & safety

Safe to run on a computer you're responsible for

A troubleshooting tool shouldn't leave you with a second problem. Here's what Muon Insight does, what it asks before doing, and what it never touches.

01Isolation

Every module runs in its own process

Modules don't run inside the app. Each one runs in its own process, isolated from the app, and you can cancel a running task.

02Confirmation

Changes wait for you

Diagnostics only read. Actions that change anything ask for explicit confirmation before they start.

Diagram of modules running in separate processes

03Remote computers

Your identity, and nothing left behind

Remote runs use WinRM with your own signed-in Windows identity, so they can only do what your account is already allowed to do. Files staged on the remote computer are removed after each run.

Muon Insight never changes

  • WinRM TrustedHosts
  • Firewall rules
  • WinRM listeners
  • Credentials

04Controls

Built for managed environments

  • Credentials stay in Windows

    ServiceNow credentials are stored in Windows Credential Manager, never in configuration files.

  • Signed content

    Content repository snapshots can be signed, and computers accept content only from a pinned publisher certificate.

  • Admin features are gated

    The Administration page appears only for members of approved Active Directory groups or approved users.

  • Locked settings

    Configuration is layered, and administrators can lock the settings that matter.

  • Redaction in reports

    Report and support bundle exports support configurable redaction, so you decide what gets shared.

  • Clear about elevation

    Muon Insight runs as administrator and asks for elevation when it starts.

Reporting a security issue

If you think you've found a security problem in Muon Insight, please report it privately using GitHub's Report a vulnerability button on the repository's Security tab. Please don't post details in a public issue.

[TODO: enable private vulnerability reporting on the GitHub repository; add a security email and /.well-known/security.txt once email exists]

Your data stays with you

Muon Insight doesn't send data to Muonix Labs. It connects only to the computers and services you point it at: remote computers over WinRM, your own content repository, or your ServiceNow instance. The Chrome log collection module, when you run it, opens Google test pages in Chrome to capture network logs.

Muon Insight has no AI features. The websites set no cookies and use no analytics.

Free public beta

Try it on your next ticket

Muon Insight is free during the public beta. Download it from GitHub.