Security & deployment
Agentless on the host, read-only against production, and running on commodity Linux you control. Built to be the shortest security review in the category.
Nothing installed on the mainframe
The solution uses the vendor SQL/ODBC access layers your shop already licenses — Db2 Connect, IBM i Access, Datacom/IDMS Server, Adabas SQL Gateway, IMS ODBM. No agents, no host code, no change tickets on z/OS.
Read-only, uncommitted-read isolation
All access runs read-only under UR isolation — no locks are taken on production data. Pushdown aggregates return one result row; column streams move in bounded 10,000-row fetches.
Environment variables only
The INI configuration declares connections, tables, and rule chains. Credentials are supplied via environment variables and are never stored in the file.
The report shows the exact SQL
Every check carries a registry ID and disclosure notes (RFC 5322 subset, E.164, NANP, IANA TLD snapshot), and the report discloses the exact SQL that ran on the host. Nothing in the scorecard is a black box.
Deployment requirements
| Component | Requirement |
|---|---|
| Server | Single Linux server (x86-64), customer-provisioned — no cluster, no appliance |
| Reference benchmark host | 8-core, 256 GB Azure instance, 2 TB SSD |
| Host connectivity | Customer-licensed vendor SQL/ODBC layers (see datastore coverage) |
| Mainframe changes | None |
Bring your security team to the demo.
The agentless architecture usually answers their first ten questions before they ask them.
Request a demo