Telemetry is never writable
The public API cannot be talked into accepting connection records.
PUBLIC API
Use tenant-scoped credentials, cursor pagination, stable error codes, and supported SDKs for TypeScript, Python, and Go.
Context
If the data is yours, you should be able to get it without a screenshot. A read API on a privacy product is also the surface most likely to become a leak, so its shape matters more than its feature list.
A versioned read API, authenticated with tenant-scoped credentials. Cursor pagination. Generated SDKs for TypeScript, Python, and Go, published from the OpenAPI description. The interactive console lives on the developer portal.
On this page
The public API cannot be talked into accepting connection records.
When a quota is hit, a documented error code returns with a retry hint, not a silent truncation.
The read API starts on Pro.
Collection boundary
Aggregates, conformity results, posture results, alerts, audit records, configuration objects, and device inventory, all scoped to the calling principal's tenant, derived server-side.
A telemetry write. Write scope is limited to configuration objects. There is no endpoint, parameter, header, or scope that makes telemetry writable. A tenant identifier supplied by a caller is ignored — scope comes from the authenticated principal, never from input.
Coverage is not complete. Some traffic paths are not observable from the interfaces we use, and geolocation is advisory rather than authoritative.
Not included
Read-only
Read-only, higher quota
Read plus configuration write