What UprootSecurity can see: the Uproot Agent and your connected tools
The Uproot Agent sends two kinds of thing and nothing else: a short list of details identifying the machine it runs on, and a passed-or-failed verdict for each of the seven security checks it runs — with a short note when a check fails. It has no way to send file contents, browsing history, keystrokes, screenshots, location, a list of installed applications, or a list of running processes — our side rejects anything outside that list, and there's nowhere for the rest to go. Connected tools work on the same principle at company scale: UprootSecurity reads posture from your tools to prove your controls, and doesn't change your infrastructure.
What the Uproot Agent sends — the complete list
What it sends | What it has no way to send |
|---|---|
The device's name and hostname | The contents of any file — documents, code, anything on disk |
Which operating system family it is | Browsing history |
Six descriptors: manufacturer, model, operating system distribution, operating system release, processor architecture, and the agent's own version | Keystrokes or screenshots |
One word per check — passed or failed | Location |
When a check fails, a short note describing what it found | A list of installed applications, or of running processes |
The timing is just as narrow. The identity and hardware details go up when the agent is first connected. On every later check-in it re-sends only those descriptors — the agent checks in periodically, and each check-in carries nothing new. Verdicts go up when the checks report.
That's the whole list. It isn't a policy we've written down and hope to keep; it's what our side accepts. Anything else is refused on arrival.
The checks read settings, not data
The seven checks are local yes-or-no questions the agent asks the machine it's installed on:
- Is disk encryption switched on?
- Is the firewall running?
- Does the screen lock?
- Are security updates being applied automatically?
- Is malware protection active?
- Is logging on?
- Does the password policy meet the bar?
The agent reads the setting and reports the verdict. It doesn't read the data the setting protects — it confirms the disk is encrypted, it doesn't look at the disk.
Your employees see everything the agent reports about their machine
Everything the agent reports about a person's machine is visible to that person in My Uproot: the device details, and every check result with the reason for each failure. Nothing the agent reports about their machine is hidden from them.
That's the line to give a hesitant colleague. They don't have to take your word for what's being sent — they can open the portal and read it themselves.
The agent reports posture; it doesn't act
The Uproot Agent doesn't change settings, install software, or lock or wipe anything.
So a failed check is fixed by the employee, on their own machine, using the instructions shown in My Uproot. An admin can see that a device fails a check; an admin can't switch the setting on from here.
What connecting a tool grants
Cloud accounts — AWS, Azure and GCP — connect through read-only roles.
Everything else connects over OAuth, and the exact permissions being requested are listed on that integration's setup page before you approve the connection. Read that list. It's shown to you at the moment of the decision and it's the authoritative answer for your provider — more precise than anything a general article can tell you.
We won't tell you that every scope on every provider is a read scope; some providers bundle permissions more broadly than we'd write them. What holds across every integration is this: UprootSecurity reads posture from your tools to prove your controls. It doesn't change your infrastructure.
What we hold about a person
Two sources, both short.
From your identity provider: their name, work email, job title, whether multi-factor authentication is on, and whether their account is active.
From the platform itself: which policies they've accepted, whether they've completed training, and their device's check results.
That's the record. It exists because your framework asks you to prove your people are managed — that access is controlled, policies are acknowledged and training is done.
