Egress, data classes and the delivery ledger
Nothing leaves a deployment until an admin turns on egress for a destination with a host allowlist, protocol, credential reference and data class. Foxborne records every delivery in a ledger with its payload SHA-256 and the response.
On this page11
A path out of your network is a decision an admin makes, one destination at a time. Each destination carries one data class, which limits what may leave in each message. A ledger records each delivery, byte for byte.
Egress is off until an admin turns it on#
The Destinations tab of Integrations opens with four figures: Egress, Destinations on, Deliveries, last 7 days and Delivery. Egress reads Off by default, and Delivery reads At least once, with "5 attempts, then dead letter".
Destinations on counts the destinations with egress on and how many sit outside the enclave. The deliveries figure links to any dead letters.
The Hosting page keeps the complete list under Outbound connections. Its fixed rows say that Foxborne, Inc. and map or tile services receive nothing, and that SAML assertions arrive from your identity provider. Every destination whose egress is on follows, with its purpose, first host and class.
In the example dataset, the email row reads "Alert email to smtp.hfr.internal:587. Data class L0."
The panel notes: "Destinations are managed in Integrations. Egress is off by default, and an admin turns on each one."
What an admin sets for each destination#
Set up (or Configure, once saved) in a destination's drawer opens the settings. Add destination, at the top right of the Destinations tab, lists every destination not configured yet, grouped Notify, Ticketing and Forward logs. Pick one and select Continue to open the same settings. The dialog notes: "Nothing is sent until an admin turns on egress for this destination." Saving writes Configured integration to the audit log.
| Field | What it decides |
|---|---|
| Host allowlist | "One host:port per line. Foxborne connects to these hosts and no others." Wildcards and schemes are refused. |
| Protocol | One of the destination's own protocols, such as SMTP submission, 587 STARTTLS or Standard Webhooks v1, HMAC-SHA256. |
| Target | Its label depends on the destination: Channels for Mattermost, Project and issue type for Jira, Streams for syslog, Index and source type for Splunk HEC. |
| Credential reference | "A secret store path, never the secret." It takes a Secrets Manager name such as secretsmanager:foxborne/int/name or a Vault path such as vault:kv/foxborne/int/name. |
| Data class | L0 or L1. L2 is never available here: "L2 moves only through Export, with approval." |
Foxborne reads the credential at send time and never shows or stores its value. A value that looks like a secret itself, such as a whsec_ key or a URL, is refused with "That looks like a secret itself. Enter where it is stored".
Turning egress on and off#
The Egress column holds a switch for each configured destination. Turning it on opens Turn on egress to destination, which repeats the hosts, the data class and the protocol. It notes: "Every delivery is written to the delivery ledger."
Only an admin can open egress. An admin confirms with a hardware security key: "You confirm this as an admin with your hardware security key." Anyone else picks the admin from Admin confirming, and that admin confirms on the same screen.
The audit log records Enabled egress with the class and first host, such as L1 to splunk-hec.hfr.internal:8088. When another admin confirmed, the detail adds ", confirmed by" and that admin's name.
Turning egress off asks Turn off egress to destination. Foxborne "stops sending to" the first host "at once", and alerts routed there are still recorded in Foxborne. For Syslog over TLS the dialog adds: "Your SIEM stops receiving the audit log and the delivery ledger."
The audit log records Disabled egress.
A destination outside the enclave also needs a route. Its dialog warns "Deliveries will fail until your network team opens a path to" the host, or "until a VPC endpoint for this service exists." The allowlist limits where Foxborne may connect, and your network decides whether the path exists.
Three data classes#
The Data classes panel states the rule: "Everything outside the enclave gets L0 by default. L1 goes only to destinations the program has authorized for CUI. L2 moves only through Export, with approval."
| Class | The console's definition | How a destination gets it |
|---|---|---|
| L0 | "Metadata: rule, severity, vehicle alias, UTC time and case link." | The default. |
| L1 | "Summary with values. Treat it as CUI." | Choose L1 and tick The program has authorized this destination for CUI, which is "Required for L1." |
| L2 | "Evidence files. They move only through Export, with approval." | Never on a destination. See Export formats and evidence bundles. |
The case link in an L0 message opens only for people who can sign in to your deployment. The values stay behind your identity provider.
PagerDuty is limited to L0: its L1 choice reads "This destination is limited to L0 metadata." A test message "carries no data", so it is always L0 whatever the destination's class.
Why L0 is the default outside the enclave#
DFARS 252.204-7012 sets the floor. Under paragraph (b)(2)(ii)(D), an external cloud service that stores, processes or transmits covered defense information must meet security requirements equivalent to the FedRAMP Moderate baseline.
Not every destination clears that bar. The FedRAMP Marketplace lists PagerDuty as "FedRAMP Certified, Class B (Low)", authorized on 10 March 2025, so PagerDuty receives L0 and nothing more.
AWS GovCloud adds a second limit. Its SNS guidance keeps export-controlled data out of email, HTTP endpoint, mobile push and out-of-GovCloud SQS subscriptions, and out of topic names and subjects. The alert says where to look, and the values stay inside the enclave.
Markings travel with content#
"L1 and L2 payloads carry the program's banner string." An L1 payload carries it in its marking field, for example "marking": "CUI" in the example dataset. A summary in a SIEM or a file in a bundle arrives already marked.
An admin sets the banner and the designation indicator under Settings, in the Marking panel. See Markings and handling and CUI marking.
No program or vehicle names in resource metadata#
"No program or vehicle names go into cloud resource names, tags or subjects, following the GovCloud guidance on metadata." Name the queues, topics, buckets and indices you create for Foxborne the same way. For OpenSearch, the AWS guidance extends to index names, document IDs, aliases and snapshot names.
Cryptography#
The console's guardrail reads: "TLS 1.2 or later with FIPS suites and TLS 1.3 support, as NIST SP 800-52 Rev. 2 requires."
| Where | What Foxborne uses |
|---|---|
| Every TLS connection | TLS 1.2 or later with FIPS-based cipher suites, with TLS 1.3 support |
| Machine endpoints | Mutual TLS: both sides present certificates |
| Syslog | RFC 9662: TLS 1.2 mandatory, TLS 1.3 recommended and TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 required |
| Webhooks | An HMAC-SHA256 signature in Standard Webhooks headers, or Ed25519 under scheme v1a |
| AWS GovCloud | FIPS endpoints, such as s3-fips.us-gov-west-1.amazonaws.com |
FIPS in this table describes cipher suites and AWS endpoints. It is not a validation of Foxborne.
The delivery ledger#
Every outbound delivery goes into the delivery ledger with its destination, data class, payload SHA-256 and response. The ledger itself is forwarded to the SIEM. The Delivery ledger tab lists the last 7 days, newest first, 25 rows a page. Each row opens with an icon for what it delivered: an alert, an automation, a case update, findings, the audit stream, an export or a test.
| Column | What it shows |
|---|---|
| Time, UTC | When the first attempt was made |
| Delivery | What was sent, such as run.closed_out, R-0934, then the destination and its target |
| Class | L0, L1 or L2 |
| Payload SHA-256 | The first 8 and last 4 hex characters; hover for the full hash |
| Response | The last answer and the attempt count, such as Delivered on attempt 2 |
The filters split the ledger into All, Alerts, Automations, Audit stream, Exports, Tests, Retried and Dead letters. All destinations narrows it to one destination.
Open a row for its drawer. Delivery gives the status, the first attempt, the data class and the Idempotency key. About links the incident, event, run, alert firing, automation run or export.
Attempts lists each try with its time, answer and duration. Request shows the request line and any headers, and Payload, as sent shows the exact bytes.
The SHA-256 covers "these exact bytes in UTF-8". For email it includes the CRLF line endings SMTP sends, and Copy keeps them. A receiver that kept a payload can hash it and match the ledger.
Delivery semantics#
The console states the policy: "At least once. A 30 s timeout and up to 5 attempts, backing off 30 s, 2 min, 8 min and 32 min, then the dead-letter queue. Each delivery carries an idempotency key, and any dead letter can be replayed."
| Status | What it means |
|---|---|
| Delivered | The destination accepted it, on the first attempt or a later one |
| Retrying | An attempt failed, and the next one is scheduled |
| Dead letter | 5 attempts failed; the delivery waits in the dead-letter queue |
| Failed | A test that did not arrive. Tests are not retried |
The example dataset has one dead letter: run.closed_out, R-0934 to the Generic webhook (HMAC). Its attempts ran at 15:58:31, 15:59:01, 16:01:01, 16:09:01 and 16:41:01 UTC, each answered 503 Service Unavailable. The gaps are the 30 s, 2 min, 8 min and 32 min of the policy.
A dead letter shows as a red note above the ledger, with Details and Replay. Replay sends it again under the same idempotency key, once egress to that destination is on. The attempt line then reads "Replayed, delivered on attempt" with its number, and the audit log records Replayed delivery.
Related#
- Alerts routes alert rules to the destinations above.
- Webhooks shows how a receiver checks the signature and deduplicates.
- Forward logs to your SIEM streams the audit log and the ledger to your SIEM.
- Export formats and evidence bundles covers L2 and its approvals.