Palantir Foundry is designed to provide secure collaboration in almost any environment, from the cloud to the edge. If you are running a Foundry data connector agent outside of Palantir’s managed SaaS platform, such as in your own data center or on your own cloud, follow the guidance on this page to protect your installation.
If your Foundry data connector agent is deployed on bare-metal hardware, such as in a data center, it is crucial to implement strong physical security controls. Access to servers running a Foundry data connector agent should be restricted to authorized personnel only.
Any access to Foundry servers should be time-bound, documented, and follow industry best practices. Unauthorized access to the hardware running Foundry could allow an adversary the opportunity to perform various attacks and subvert security controls.
The Foundry data connector agent implements object-level encryption as part of the data ingestion process. The data connector receives cryptographic key material from the Foundry platform, encrypts the object, and submits it to the Foundry API for ingestion and storage.
All data transmitted between the data connector and the Foundry API is encrypted using strong encryption protocols and ciphers.
It is important to segment and separate your Foundry data connector installation from the rest of your environment. Below is a list of best practices for accomplishing this.
It is important to strictly control network traffic originating from your Foundry data connector installation with egress (outbound) controls.
Use network security controls to protect your Palantir Foundry data connector installation.
Harden the servers used for your Foundry data connector installation using industry-standard configuration guidance such as CIS or NIST controls.
Use host security controls to protect your Foundry data connector installation.
It is important to strictly control privileged access to your Foundry data connector installation.
The Foundry data connector includes the ability to self-update to the latest supported version, minimizing the maintenance requirements for your operational staff.