What the agent does with your data

The agent is the only part of Cenya that touches your network. This page describes exactly what it reads, what it never does, and where the data goes.

Where it runs and who it talks to

The agent is a small Python process or Docker container inside your network. It only makes outbound HTTPS connections to your own Cenya installation. It opens no ports, stores nothing on disk, and never talks to us.

What it asks, protocol by protocol

Ping and the ARP table: which hosts are alive and their MAC addresses. Reverse DNS: names. SNMP v2c or v3, read-only GET and WALK: system description and name, interfaces, IP addresses, LLDP/CDP neighbors, UPS battery and load (RFC 1628). SSH: identification commands such as uname, show version or display version; on network equipment, and only if you enable it, the configuration export (show running-config on Cisco, /export on MikroTik). WinRM: read-only PowerShell queries for name, domain, manufacturer, model, serial and interfaces. Hypervisors (vCenter, Proxmox, Hyper-V, XCP-ng): the list of hosts and virtual machines with vCPU, RAM, disk and state.

What it never does

It never writes to a device, never changes a configuration, never runs a command that modifies anything, never scans outside the subnets you configure, and never sends anything to Cenya the company.

Credentials

Credentials are stored encrypted in your Cenya database, delivered to the agent in memory over HTTPS on each heartbeat, and never written to disk by the agent. Reports shown in the interface never contain a secret: an SNMP community is referred to by its position, a user by its name.

What reaches your server

Findings: names, IPs, MACs, interfaces, vendor, model, serial, neighbors, virtual machines and UPS measurements, plus configuration snapshots if enabled. Findings wait in a review tray. Nothing is written to your inventory until a person accepts it, and data entered by hand is never overwritten by the agent.

Turn things off

Config capture can be disabled in Settings → Agents or with the NETINVENTORY_CAPTURE_CONFIGS=0 environment variable. Each protocol only runs if you give it credentials.

Read the code

The agent's source code is public under the Apache 2.0 license.

View on GitHubRepository published with the beta