Secure-by-Design

Our architecture ensures the highest level of security based on the following core principles:

1 Single Collector Agent with Minimal Permissions

  • Installed in the customer’s network
  • Runs with minimal resource requirements (non-dedicated Windows host, 2GHz CPU, 1GB memory)
  • Light footprint (~0.5% CPU average)
  • Least-privilege operation, no direct DB content access (DMV & System Views on MSSQL, $V on Oracle)

2 Secure Encrypted Transmission

  • All data is encrypted in transit and at rest
  • Prevents unauthorized access and interception

3 Highest Security Standards in a Multi-Tenant* Datacenter

  • Complies with leading security frameworks and regulations
  • Provides data isolation between tenants using a set of secure protocols

*For customers with more stringent compliance requirements, we offer premium security options

4 Secure Access to Web Application

  • Enforced security controls, including login failure limits, session protection, and IP-based access restrictions
  • Support for enhanced authentication methods, including 2FA and SSO

5 Secure Remote Actions & Custom Actions (Optional Responsiveness)

When Responsiveness is enabled in the AimBetter configuration, the AimBetter Agent can securely execute approved administrative operations, including built-in remote actions (such as restarting services or terminating processes) and customer-defined Custom Actions.

To maintain a secure-by-design architecture:

  • Agent Responsiveness must be explicitly enabled in the AimBetter Configuration. By default, remote actions and Custom Actions are disabled.
  • The AimBetter Agent service runs under a Windows account with the permissions required to perform the configured actions.
  • Administrative permissions are used only by the local Agent running inside the customer’s environment and are never exposed through the web application.
  • Every remote or custom action requires One-Time Password (OTP) verification, with the OTP sent to the authenticated user’s registered email address.
  • The action is executed only after successful OTP validation, ensuring that user authentication and operating system privileges are independently verified.
  • All actions are initiated by an authenticated user, executed by the local Agent, and can be fully audited.
  • Custom Action scripts are stored locally on the AimBetter Agent and are validated before execution. The Agent verifies that the script file has not been modified since it was configured, ensuring that only the approved version of the script can be executed.

This layered security model ensures that privileged operations can be performed remotely without compromising security. Even when elevated operating system permissions are required, each action requires explicit user authorization through OTP verification before execution.

What Data Does AimBetter Collect?
What Data Does AimBetter Collect?
  • Windows Servers:

    Real-time data on running processes, CPU and memory usage, disk performance, network activity, services, time settings, and system events, based on WMI.
  • Linux Systems:

    Gathers OS version, active processes, CPU and memory stats, I/O performance, disk and swap usage, network traffic, and service status through standard system commands.
  • Microsoft SQL Server:

    Collects query execution statistics, wait times, session and transaction activity, index and storage usage, high availability status, and system configuration using DMVs and system views.
  • Oracle Databases:

    Extracts performance data, including SQL performance, session tracking, job scheduling, storage, configuration, and critical alert logs from V$ views and DBA tables.


You can check all the data sources in the Agent Viewing List

Data Collection Intervals
Data Collection Intervals
  • Every module clearly displays its data collection interval directly in the Agent UI
  • Intervals are designed to balance near real-time visibility with minimal system overhead
  • Different data types are collected at different frequencies, based on their nature and operational impact
  • Modules can be deactivated at any time, giving customers complete control over what is monitored

All data collection intervals are directly exposed in the AimBetter Agent, ensuring that customers can confidently deploy AimBetter in regulated, high-load, and security-sensitive environments, with complete visibility and control at all times.

More about the AimBetter Agent.

Security Assurance & Validation

Beyond secure product architecture, AimBetter continuously validates and strengthens its security posture through proactive testing and assessment designed to identify vulnerabilities, reduce risk, and ensure ongoing protection against evolving threats.

Manual Web Penetration Testing


AimBetter performs periodic manual Web Penetration Testing to assess application-layer security, identify business-logic issues, authentication weaknesses, authorization flaws, and other vulnerabilities that require expert human analysis.

Automated Security Validation with ARYA


In addition to manual testing, AimBetter uses ARYA to validate real-world security exposure across internal, external, and ransomware-related attack scenarios.

ARYA helps assess:

  • External exposure and internet-facing risks
  • Internal attack paths, lateral movement, and privilege escalation risks
  • Ransomware resilience and potential propagation paths
  • Misconfigurations and exploitable weaknesses
  • Effectiveness of remediation through targeted retesting

By combining manual Web Penetration Testing with ARYA’s automated validation, AimBetter enables continuous security assessment and improves risk detection across realistic attack scenarios.

Premium Security

On top of AimBetter’s secure-by-design architecture, we offer additional security conditions for organizations with stringent compliance requirements, such as financial institutions, government agencies, and healthcare organizations, that demand further separation from the general environment.

🔒 Premium 1
  • Dedicated database for storing performance data and analytics, fully secured.
  • Dedicated URL for the web application with a dedicated service user and IP restriction for database access.

🔒🔒Premium 2
  • Dedicated database instance and dedicated web server, accessible only by the company’s users.
  • Additional security enforcement tailored to the company’s specific requirements.

These premium security conditions incur additional infrastructure and maintenance costs and require an on-demand quotation based on the customer’s specific needs.

Secure-by-design additional references

ISO 27001

We are proud to announce that AimBetter has completed the ISO 27001 Compliance process. ISO…

Agent Viewing List

As part of AimBetter’s Zero Trust policy, our agent access is restricted to the Data…
Menu
AimBetter We use cookies to ensure the website functions properly and improve user experience. You can choose which types of cookies to enable.
Cookie Selection


Skip to content